07-06-2017 06:38 AM - edited 03-12-2019 02:39 AM
Hi
Cisco ASA syslog message 302013 (ASA-6-302013: Built inbound TCP connection) does it really means a established TCP connection (after 3 way handshake) or does it mean that just the SYN packet is allowed through the firewall?
Regards,
Aneesh Kaimal
07-06-2017 08:21 AM
I believe it is the inital SYN packet that triggers the syslog message.
You can see further detail of a given connection by checking the flags as described in this document:
http://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/113602-ptn-113602.html
06-22-2022 11:04 AM
Hi Aneesh,
I have enabled syslog messages to a remote syslog server set to logging level 6 but however I have never seen this events 302013,302014,302015,302016 at my end. Can you let me know how did you get the same configured and is it like by default this events are disabled to log.
Regards,
rraj1788
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide