cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
471
Views
0
Helpful
3
Replies

Doubt with Log

Hello All

I have some doubts with log of ASA...

If someone help me

Jul 23 16:54:42 11.11.11.11 %ASA-4-313005: No matching connection for ICMP error message: icmp src outside:172.20.20.20 dst inside:172.19.19.19 (type 3, code 3) on outside interface.  Original IP payload: udp src 172.19.19.19/53 dst 172.20.20.20/61126.

172.20.20.20 = workstation

172.19.19.19 = server

Why this message?

Maybe any drop in my network because of it???

How can I fix it?

Thanks anyway.

Diego

3 Replies 3

Jennifer Halim
Cisco Employee
Cisco Employee

That means port is unreachable and from your error message since it's UDP/53, the DNS resolution either does not work, or it already passes through the timeout for DNS reply. As a safety measure the firewall will drop the packet if it doesn't receive the DNS reply within certain period of time, this is to prevent against DNS attack.

Hi Jennifer, thanks for your answer..

hum... I have the port udp/53 allowed...

Maybe a problem with the server??? Or anything I need to do on ASA?

Yeah, seems like problem with the server if port is already allowed on the ASA.

Review Cisco Networking products for a $25 gift card