Teardown missing for built inbound connection on Cisco PIX 6.3

Unanswered Question
May 8th, 2012


In my syslog server configured for Cisco PIX 6.3,

I see lot of Built and teardown connections.

Logic says if something is built then there should be a teardown.

But I do not see teardowns for some connections even though I know that path is already broken long time ago.

See below.

May  3 09:44:16 ::ffff: May 03 2012 12:50:32 cfwprd1a : %PIX-6-302013: Built inbound TCP connection 954594374 for dcn: ( to dmz: (

Why is there no teardown for the above in my syslog server?

And this is not just one - there are many meesages that do not have teardowns.


I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
varrao Tue, 05/08/2012 - 11:39

Hi Kunal,

Check the following, I guess you migth have this message diasable, check:

show run logging

if it is:

no logging message 302014

then apply:

logging message 302014

I guess you might have this log suppressed on the ASA.



Security Team,
Cisco TAC

kunal-united Wed, 05/09/2012 - 04:10


Please check this.

logging on

logging timestamp

logging standby

logging monitor debugging

logging buffered warnings

logging trap informational

logging history critical

logging device-id hostname

logging host dcn

logging host dcn

logging host apps

no logging message 106023


varrao Wed, 05/09/2012 - 07:19

Hi Kunal,

Can you filter your syslog server for the connection ID 954594374?? Moreover, are you able to see the Teardown in the ASDM log viewers, and the ASA log buffer? Can you also share the output of "show logging-queue"??

Varun Rao
Security Team,
Cisco TAC

kunal-united Wed, 05/09/2012 - 08:19

# sh logging queue

        Logging Queue length limit : 512 msg(s), 6251808 msg(s) discarded.

        Current 16 msg on queue, 512 msgs most on queue

I have all logs on the syslog server.

And I cannot see teardowns for few connections that were built.



This Discussion