×

Warning message

  • Cisco Support Forums is in Read Only mode while the site is being migrated.
  • Cisco Support Forums is in Read Only mode while the site is being migrated.

Deny UDP reverse path check

Unanswered Question

We have a ASA up for a few years now and I am finally trying to understand some of the syslog info.  I configured it yesterday to email any Alerts and Emergency messages.  In the past 21 hrs I have received 511 (I'm glad I had conversation view enabled in Outlook).  I have many questions but I will start with why, throughout the night, I receive (over 100) something like this:

<185>Jan 18 2012 07:23:32: %ASA-1-106021: Deny UDP reverse path check from 169.254.146.189 to 198.41.0.4 on interface inside

Looks like a Windows client with a self assigned IP. We have an open wireless "guest" network for students to use for the smart phones, etc..., which is always out of IP addresses.    What is it trying to do? What is 198.41.0.4 (always different)?  If these are harmless, can I stop it from reporting them?

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
Marcin Latosiewicz Wed, 01/18/2012 - 06:52
User Badges:
  • Cisco Employee,

Michael,


All syslogs ASA 8.3 are referenced here:

http://www.cisco.com/en/US/docs/security/asa/asa83/system/message/logmsgs.html

You can easily google for different version of this document.


As far as checking what that IP is. Best start by checking whois :-)


In this case it's verisign ... not sure why anyone would send UDP to it ... you might need to sniff traffic.

whois 198.41.0.4

#

# Query terms are ambiguous.  The query is assumed to be:

#     "n 198.41.0.4"

#

# Use "?" to get help.

#


#

# The following results may also be obtained via:

# http://whois.arin.net/rest/nets;q=198.41.0.4?showDetails=true&showARIN=false&ext=netref2

#


NetRange:       198.41.0.0 - 198.41.3.255

CIDR:           198.41.0.0/22

OriginAS:

NetName:        INTERNIC1

NetHandle:      NET-198-41-0-0-1

Parent:         NET-198-0-0-0-0

NetType:        Direct Assignment

RegDate:        1993-01-04

Updated:        2005-01-13

Ref:            http://whois.arin.net/rest/net/NET-198-41-0-0-1


OrgName:        VeriSign Infrastructure & Operations

OrgId:          VIO-2

Address:        12061 Bluemont Way

City:           Reston

StateProv:      VA

PostalCode:     20190

Country:        US

RegDate:        2002-07-11

Updated:        2012-01-03

Ref:            http://whois.arin.net/rest/org/VIO-2


OrgAbuseHandle: NETWO480-ARIN

OrgAbuseName:   Network Admin

OrgAbusePhone:  +1-703-948-4300

OrgAbuseEmail:  [email protected]

OrgAbuseRef:    http://whois.arin.net/rest/poc/NETWO480-ARIN


OrgTechHandle: NETWO480-ARIN

OrgTechName:   Network Admin

OrgTechPhone:  +1-703-948-4300

OrgTechEmail:  [email protected]

OrgTechRef:    http://whois.arin.net/rest/poc/NETWO480-ARIN


#

# ARIN WHOIS data and services are subject to the Terms of Use

# available at: https://www.arin.net/whois_tou.html

#

Actions

This Discussion