cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1886
Views
0
Helpful
0
Replies

ASA Firewall - Invalid transport field for protocol

cos
Level 1
Level 1

Hello, good afternoon

We have implemented ASA firewall platform and would like to get help with the security events:
  ASA 5550
 ASA Version: 8.0(4)
 ASDM Version: 6.1(5)51

    
From ASA we send syslog to remote server SIEM. Our SIEM correlated events and generating the following offense:
  Event Information
 Event Name:    Invalid transport field for protocol
 Low Level Category:    System Error
 Event Description:    This message appears when there is an invalid transport number, in which the source or destination port number for a protocol is zero. The protocol value is 6 for TCP and 17 for UDP.

    ASA Firewall event:
    <164>Jul 02 2014 15:40:19: %ASA-4-500004: Invalid transport field for protocol=UDP, from ac1_autoprestacio/21128 to 1.0.0.0/0

I have a lot connections from my firewall to public IP addresses whose destination port is 0.

indecision

Any idea?
How can we avoid these events?

Regards and thanks,

 

Diego C

0 Replies 0
Review Cisco Networking for a $25 gift card