cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
398
Views
0
Helpful
2
Replies

Pix vs ASA Log Entries

jogillis
Level 1
Level 1

I have noticed that connections going from one dmz to another have two entries in the ASA log, one "inbound" and one "outbound". I did not remember seeing this when we had a Pix. Did I just miss it before or is this a new feature with the ASA.

2 Replies 2

abinjola
Cisco Employee
Cisco Employee

can you post a log here , as there has been so changes in terms of how a connection log entry is created in ASA or Pix

Here are some examples

<166>Mar 03 2008 00:00:14 asafp1 : %ASA-6-302013: Built inbound TCP connection 416002445 for dmz2:10.2.3.80/1018 (10.2.3.80/1018) to inside:192.168.6.22/5

14 (192.168.6.22/514)

<166>Mar 03 2008 00:00:14 asafp1 : %ASA-6-302013: Built outbound TCP connection416002446 for pddmz:192.168.6.22/514 (192.168.6.22/514) to inside:10.2.3.8

0/1018 (10.2.3.80/1018)

<166>Mar 03 2008 00:00:14 asafp1 : %ASA-6-302013: Built outbound TCP connection416002448 for pddmz:192.168.6.22/1021 (192.168.6.22/1021) to inside:10.2.3

.80/1017 (10.2.3.80/1017)

<166>Mar 03 2008 00:00:14 asafp1 : %ASA-6-302013: Built inbound TCP connection 416002447 for dmz2:10.2.3.80/1017 (10.2.3.80/1017) to inside:192.168.6.22/1

021 (192.168.6.22/1021)

<166>Mar 03 2008 00:00:14 asafp1 : %ASA-6-302013: Built inbound TCP connection 416002463 for pddmz:192.168.6.21/50517 (192.168.6.21/50517) to inside:10.200.

3.81/80 (10.2.3.81/80)

<166>Mar 03 2008 00:00:14 asafp1 : %ASA-6-302013: Built outbound TCP connection416002464 for dmz2:10.2.3.81/80 (10.2.3.81/80) to inside:192.168.6.21/5051

7 (192.168.6.21/50517)

Review Cisco Networking products for a $25 gift card