01-18-2012 04:45 AM - edited 03-11-2019 03:15 PM
We have a ASA up for a few years now and I am finally trying to understand some of the syslog info. I configured it yesterday to email any Alerts and Emergency messages. In the past 21 hrs I have received 511 (I'm glad I had conversation view enabled in Outlook). I have many questions but I will start with why, throughout the night, I receive (over 100) something like this:
<185>Jan 18 2012 07:23:32: %ASA-1-106021: Deny UDP reverse path check from 169.254.146.189 to 198.41.0.4 on interface inside
Looks like a Windows client with a self assigned IP. We have an open wireless "guest" network for students to use for the smart phones, etc..., which is always out of IP addresses. What is it trying to do? What is 198.41.0.4 (always different)? If these are harmless, can I stop it from reporting them?
01-18-2012 06:52 AM
Michael,
All syslogs ASA 8.3 are referenced here:
http://www.cisco.com/en/US/docs/security/asa/asa83/system/message/logmsgs.html
You can easily google for different version of this document.
As far as checking what that IP is. Best start by checking whois :-)
In this case it's verisign ... not sure why anyone would send UDP to it ... you might need to sniff traffic.
whois 198.41.0.4
#
# Query terms are ambiguous. The query is assumed to be:
# "n 198.41.0.4"
#
# Use "?" to get help.
#
#
# The following results may also be obtained via:
# http://whois.arin.net/rest/nets;q=198.41.0.4?showDetails=true&showARIN=false&ext=netref2
#
NetRange: 198.41.0.0 - 198.41.3.255
CIDR: 198.41.0.0/22
OriginAS:
NetName: INTERNIC1
NetHandle: NET-198-41-0-0-1
Parent: NET-198-0-0-0-0
NetType: Direct Assignment
RegDate: 1993-01-04
Updated: 2005-01-13
Ref: http://whois.arin.net/rest/net/NET-198-41-0-0-1
OrgName: VeriSign Infrastructure & Operations
OrgId: VIO-2
Address: 12061 Bluemont Way
City: Reston
StateProv: VA
PostalCode: 20190
Country: US
RegDate: 2002-07-11
Updated: 2012-01-03
Ref: http://whois.arin.net/rest/org/VIO-2
OrgAbuseHandle: NETWO480-ARIN
OrgAbuseName: Network Admin
OrgAbusePhone: +1-703-948-4300
OrgAbuseEmail: netadmin@verisign.com
OrgAbuseRef: http://whois.arin.net/rest/poc/NETWO480-ARIN
OrgTechHandle: NETWO480-ARIN
OrgTechName: Network Admin
OrgTechPhone: +1-703-948-4300
OrgTechEmail: netadmin@verisign.com
OrgTechRef: http://whois.arin.net/rest/poc/NETWO480-ARIN
#
# ARIN WHOIS data and services are subject to the Terms of Use
# available at: https://www.arin.net/whois_tou.html
#
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide