cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
485
Views
0
Helpful
1
Replies

logging configuration

vipinrajrc
Level 3
Level 3

Hi Experts,

Recently i implemented Kiwisyslog server in Office. from the logs it was clear that someone was trying to access our network. It was showing TCP connection denied from the src IP address<a public IP>. When i checked the IP address, that IP address was from england, also there was multiple IP address (4 or 5) from different location. and the priority level of all the message is warning. I am using ASA5505. Is it normal in everywhere???

If there any solution for this??? please reply....ASAP urgent.......

Thanks&Regards

Vipin Raj R.C

Thanks and Regards, Vipin
1 Accepted Solution

Accepted Solutions

padatta
Level 1
Level 1

Hi,

There might be illegitimate attempts to gain access from outside. We should be fine until ASA is able to deny these attempts AND the rate of such attempts are not so high as to 'kill' the ASA (like DoS).

Unless these packets are blocked somewhere on the outside, they will reach the ASA. The ASA has to perform the security check and ultimately deny them. This is fine as long as such packets are not very frequent. But if they shoot up then it would be better to block them at ISP level or on outside router.

Paps

View solution in original post

1 Reply 1

padatta
Level 1
Level 1

Hi,

There might be illegitimate attempts to gain access from outside. We should be fine until ASA is able to deny these attempts AND the rate of such attempts are not so high as to 'kill' the ASA (like DoS).

Unless these packets are blocked somewhere on the outside, they will reach the ASA. The ASA has to perform the security check and ultimately deny them. This is fine as long as such packets are not very frequent. But if they shoot up then it would be better to block them at ISP level or on outside router.

Paps

Review Cisco Networking for a $25 gift card