cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1510
Views
0
Helpful
1
Replies

logging event faddr,gaddr,laddr

rnbhatija
Level 1
Level 1

hi all,

i took over this environment, and want to cleanup some natting

im seeing logging even as follows

 

6Sep 11 201504:58:35 172.23.0.120192.168.1.37512

Teardown ICMP connection for faddr 172.23.0.12/0 gaddr 192.168.1.37/512 laddr 192.168.1.37/512

 

now i do see nat for 172.23.0.12 (DMZ) nat'ed to 209.17.183.x , to a public ip address, however i am not able to ping 172.23.0.12 from ASA, neither from a server on the DMZ network.

 

So how is that 172.23.0.12 generating event when it doesn't exists ?

 

thanks in advance

 

 

 

 

1 Reply 1

Vibhor Amrodia
Cisco Employee
Cisco Employee

Hi,

I think you would be able to see this traffic as seen in the logs.

Also , refer to this:-

http://www.cisco.com/c/en/us/td/docs/security/asa/syslog-guide/syslogs/logmsgs1.html

You can check:- "show conn address <IP>" , Captures on the ASA Interface etc to check the traffic.

Thanks and Regards,

Vibhor Amrodia

Review Cisco Networking for a $25 gift card