Solved

Help with ASDM Syslog Messages from ASA 5505

Posted on 2012-03-14
4
2,048 Views
Last Modified: 2012-03-14
Here are some informational messages i've been getting in the ASDM syslog section (getting a lot, about 5-10 per second), but they seem to be the same ones repeating over and over. I'm not very familiar with the ASA and i'm just learning, so could someone help me understand what each message is telling me? They are all labeled as severity 6, which i guess means that they are informational messages. Here they are (minus all the IPs and domain info):

1. Built outbound TCP connection
2. Built dynamic TCP translation
3. Teardown dynamic UDP translation
4. Teardown TCP connection


Also, should i disable logging for these severity messages, or maybe enable logging for another type of severity?

Thanks so much for your help!
0
Comment
Question by:jbarnette
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
4 Comments
 
LVL 11

Accepted Solution

by:
sysreq2000 earned 500 total points
ID: 37719930
That's just your router "relaying" one of your computers access to the Internet....basically the NAT translation. The router creates the TCP connection to the destination, then creates a "translation pathway" that your computer talks to the destination through, and gets it's responses from. Sorta. Hope that makes sense. :)

You probably don't need to log those as it's routine activity.
0
 

Author Closing Comment

by:jbarnette
ID: 37719965
Sounds good to me. I was getting worried. Thank you.
0
 
LVL 11

Expert Comment

by:sysreq2000
ID: 37719981
In case you're not familiar with NAT, here is a good little explanation of what your router is doing:

http://www.cisco.com/en/US/docs/security/asa/asa83/asdm63/configuration_guide/nat_overview.html#wp1096010

Each computer and device within an IP network is assigned a unique IP address that identifies the host. Because of a shortage of public IPv4 addresses, most of these IP addresses are private, not routable anywhere outside of the private company network. RFC 1918 defines the private IP addresses you can use internally that should not be advertised:

•10.0.0.0 through 10.255.255.255

•172.16.0.0 through 172.31.255.255

•192.168.0.0 through 192.168.255.255

One of the main functions of NAT is to enable private IP networks to connect to the Internet. NAT replaces a private IP address with a public IP address, translating the private addresses in the internal private network into legal, routable addresses that can be used on the public Internet. In this way, NAT conserves public addresses because it can be configured to advertise only one public address for the entire network to the outside world.

Other functions of NAT include:

•Security—Keeping internal IP addresses hidden discourages direct attacks.

•IP routing solutions—Overlapping IP addresses are not a problem when you use NAT.

•Flexibility—You can change internal IP addressing schemes without affecting the public addresses available externally; for example, for a server accessible to the Internet, you can maintain a fixed IP address for Internet use, but internally, you can change the server address.
0
 

Author Comment

by:jbarnette
ID: 37720060
Wow, great information. I'm a beginning network admin so this is perfect for understanding what's going on with our firewall and router. I'll have a look at the link and may print some of the stuff for future reference. Thanks again for your time and help, i really appreciate it!
0

Featured Post

What, When and Where - Security Threats from Q1

Join Corey Nachreiner, CTO, and Marc Laliberte, Information Security Threat Analyst, on July 26th as they explore their key findings from the first quarter of 2017.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Concerto Cloud Services, a provider of fully managed private, public and hybrid cloud solutions, announced today it was named to the 20 Coolest Cloud Infrastructure Vendors Of The 2017 Cloud  (http://www.concertocloud.com/about/in-the-news/2017/02/0…
For months I had no idea how to 'discover' the IP address of the other end of a link (without asking someone who knows), and it drove me batty. Think about it. You can't use Cisco Discovery Protocol (CDP) because it's not implemented on the ASAs.…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…
Suggested Courses

636 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question