02-13-2011 10:07 PM - edited 03-11-2019 12:50 PM
Hi All
I am facing a strange issue with FWSM firewall rules and need some help on that.
On this firewall, we have logging enabled to a log all denies for blocked ports. . This is covered in the last deny statement with port object-group as shown below.
In the recent days we found extensive deny logs for the below 6 ports and this was causing the below error message 106101 .
tcp SMTP,tcp 135,tcp 445, tcp netbios-ssn, udp netbios-ns, udp snmp
106101 The number of ACL log deny-flows has reached limit (number)
Already the max configured limit on device is 4096. So we decided to remove logging only for those specifc 6 ports and wanted to still log rest of the denies. So we modified ACL as below
Please see above where we removed logging for those specific 6 denies and moved it above the last deny rule.
Issue:
====
After we modified the acl entries as above, we see strangely that none of the denies are getting logged to the syslog server. So absolutely logging gets stopped. This is confusing becos we only wanted the firewall not to log for those specific 6 ports but now access attempt to other ports also is not getting logged.
Please let us know what might be the cause of the issue.
Regards
Solved! Go to Solution.
02-17-2011 02:35 PM
Excellent, and it's great to hear.
Please kindly mark the post answered so others can learn from your post. Thank you.
02-13-2011 10:26 PM
My suggestion would be to reload the FWSM to clear the cached flow.
However, if you would like to know the reason why it's not working as it should, I would suggest that you open a TAC case so the issue can be investigated further.
02-17-2011 05:57 AM
Thanks Jennifer
We rebooted the FWSM firewall and that solved the issue. If the issue repeats, we are planning to open a TAC case on this.
Thanks for your suggestion
Regards
S.Balaji
02-17-2011 02:35 PM
Excellent, and it's great to hear.
Please kindly mark the post answered so others can learn from your post. Thank you.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide