cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
305
Views
0
Helpful
3
Replies

Large ICMP unreachable packet

tonny_ecmyy
Level 1
Level 1

Hi there,

My IDS in PIX receive Large ICMP Unreachable Packet,But Logging In terminal monitor shows nothing about IDS although it is already set to debugging mode. Tear down tcp connection 252 for outside xxx.xxx.xxx.xxx to inside xxx.xxx.xxx.xxx 2906 tcp fins, what thats mean? what is happening in this scenario...

Thanks For helping beginner

Tonny

2 Accepted Solutions

Accepted Solutions

nkhawaja
Cisco Employee
Cisco Employee

hi,

Tear down message seems normal. It is a normal TCP termination message. About the IDS logging, could you setup a syslog server and send all messages to it. May be it will log the IDS messages.

BTW is IDS active?

Thanks

Nadeem

View solution in original post

Hi,

This link is helpful.

http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_60/syslog/pixemint.htm

i think KIWI SYSLOG's default configuration should be fine

thanks

Nadeem

View solution in original post

3 Replies 3

nkhawaja
Cisco Employee
Cisco Employee

hi,

Tear down message seems normal. It is a normal TCP termination message. About the IDS logging, could you setup a syslog server and send all messages to it. May be it will log the IDS messages.

BTW is IDS active?

Thanks

Nadeem

Hi Nadeem,

yes, the IDS is active, i'm using telnet to view the syslog, actually i want to use kiwi syslog, but i have no idea how to configure it...if u don't mind, could you give an example how to configure pix to send syslog to Kiwi syslog and how to configure that kiwi...

Thank you very much

Tonny

Hi,

This link is helpful.

http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_60/syslog/pixemint.htm

i think KIWI SYSLOG's default configuration should be fine

thanks

Nadeem

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: