ASA 5520 Logging inaccuracies

Unanswered Question
Feb 25th, 2010
User Badges:

Hi,


This may seem strange, but i am having this weird problem when looking at the ASA 5520 logging from ASDM.


When i opened up the Real-Time Logging in ASDM, i noticed that the Source and Destination IP and ports are swapped. For example, my host has an IP of 172.16.1.1, accessing a server 123.123.123.123 @ TCP 80. When i look at the traffic logging, the Source IP shows 123.123.123.123 and Source port TCP 80, destination IP shows 172.16.1.1 and Dest. Port shows some random generated high port.


I did not noticed when this problem occurred, just realised it recently while doing some checking. Any ideas what may cause this?


Or is it time to reboot the firewall?

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
Herbert Baerten Thu, 02/25/2010 - 13:48
User Badges:
  • Cisco Employee,

Which version of ASDM is this?


There is this bug:


CSCta42388    Source and Destination not correct in Real-Time Log Viewer


Fixed in 6.2(1.55) and 6.2(2.50) and later.

platinum_jem Thu, 02/25/2010 - 17:37
User Badges:

Using 6.1(5)57

Maybe thats the reason. I shall go patch up to ASDM 6.2 and see if the problem still occurs.

Thanks!

Actions

This Discussion

Related Content