08-18-2021 03:08 PM
The ICMP logs (ASA-6-302021) we are currently receiving from the ASA do not contain the byte count for the packet. Is this design intent or a config issue?
With the rise in hackers using icmp for exfil this is a critical piece of data.
TIA
Ihor
08-18-2021 03:28 PM
Can you post sample Log here to understand the issue ?
08-18-2021 03:33 PM
08-18-2021 03:59 PM
Error Message %ASA-6-302021: Teardown ICMP connection for faddr {faddr | icmp_seq_num } [(idfw_user )] gaddr {gaddr | icmp_type } laddr laddr [(idfw_user )] type {type } code {code }
Explanation An ICMP session is removed in the fast-path when stateful ICMP is enabled using the inspect icmp command. The following list describes the message values:
08-18-2021 04:03 PM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide