cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2141
Views
0
Helpful
1
Replies

Deny UDP reverse path check

mbasso1676
Level 1
Level 1

We have a ASA up for a few years now and I am finally trying to understand some of the syslog info.  I configured it yesterday to email any Alerts and Emergency messages.  In the past 21 hrs I have received 511 (I'm glad I had conversation view enabled in Outlook).  I have many questions but I will start with why, throughout the night, I receive (over 100) something like this:

<185>Jan 18 2012 07:23:32: %ASA-1-106021: Deny UDP reverse path check from 169.254.146.189 to 198.41.0.4 on interface inside

Looks like a Windows client with a self assigned IP. We have an open wireless "guest" network for students to use for the smart phones, etc..., which is always out of IP addresses.    What is it trying to do? What is 198.41.0.4 (always different)?  If these are harmless, can I stop it from reporting them?

1 Reply 1

Marcin Latosiewicz
Cisco Employee
Cisco Employee

Michael,

All syslogs ASA 8.3 are referenced here:

http://www.cisco.com/en/US/docs/security/asa/asa83/system/message/logmsgs.html

You can easily google for different version of this document.

As far as checking what that IP is. Best start by checking whois :-)

In this case it's verisign ... not sure why anyone would send UDP to it ... you might need to sniff traffic.

whois 198.41.0.4

#

# Query terms are ambiguous.  The query is assumed to be:

#     "n 198.41.0.4"

#

# Use "?" to get help.

#

#

# The following results may also be obtained via:

# http://whois.arin.net/rest/nets;q=198.41.0.4?showDetails=true&showARIN=false&ext=netref2

#

NetRange:       198.41.0.0 - 198.41.3.255

CIDR:           198.41.0.0/22

OriginAS:

NetName:        INTERNIC1

NetHandle:      NET-198-41-0-0-1

Parent:         NET-198-0-0-0-0

NetType:        Direct Assignment

RegDate:        1993-01-04

Updated:        2005-01-13

Ref:            http://whois.arin.net/rest/net/NET-198-41-0-0-1

OrgName:        VeriSign Infrastructure & Operations

OrgId:          VIO-2

Address:        12061 Bluemont Way

City:           Reston

StateProv:      VA

PostalCode:     20190

Country:        US

RegDate:        2002-07-11

Updated:        2012-01-03

Ref:            http://whois.arin.net/rest/org/VIO-2

OrgAbuseHandle: NETWO480-ARIN

OrgAbuseName:   Network Admin

OrgAbusePhone:  +1-703-948-4300

OrgAbuseEmail:  netadmin@verisign.com

OrgAbuseRef:    http://whois.arin.net/rest/poc/NETWO480-ARIN

OrgTechHandle: NETWO480-ARIN

OrgTechName:   Network Admin

OrgTechPhone:  +1-703-948-4300

OrgTechEmail:  netadmin@verisign.com

OrgTechRef:    http://whois.arin.net/rest/poc/NETWO480-ARIN

#

# ARIN WHOIS data and services are subject to the Terms of Use

# available at: https://www.arin.net/whois_tou.html

#

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: