Running ASA 5510 with Software Version 8.2(2)
Device Manager 6.2(5)
We have threat detection enabled and shunning of hosts enabled .
We are seeing consistent logging of even 733100:
The source and destination IPs are not being shown for any of these scans . Is there a setting that I am missing ? Obviously we cannot shun any hosts if we don't have a host IP address .
Any input would be greatly appreciated.
As per your description , I think you only have the Basic Threat Detection enabled on the ASA device.
This syslog will never show the IP address. If you want to check the statistics per IP address basis , you would have to configure the Threat Detection Statistics on the ASA device:-
Thanks and Regards,
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: