cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
723
Views
0
Helpful
2
Replies

ASA 5520 Logging inaccuracies

platinum_jem
Level 1
Level 1

Hi,

This may seem strange, but i am having this weird problem when looking at the ASA 5520 logging from ASDM.

When i opened up the Real-Time Logging in ASDM, i noticed that the Source and Destination IP and ports are swapped. For example, my host has an IP of 172.16.1.1, accessing a server 123.123.123.123 @ TCP 80. When i look at the traffic logging, the Source IP shows 123.123.123.123 and Source port TCP 80, destination IP shows 172.16.1.1 and Dest. Port shows some random generated high port.


I did not noticed when this problem occurred, just realised it recently while doing some checking. Any ideas what may cause this?

Or is it time to reboot the firewall?

2 Replies 2

Herbert Baerten
Cisco Employee
Cisco Employee

Which version of ASDM is this?

There is this bug:


CSCta42388    Source and Destination not correct in Real-Time Log Viewer

Fixed in 6.2(1.55) and 6.2(2.50) and later.

Using 6.1(5)57

Maybe thats the reason. I shall go patch up to ASDM 6.2 and see if the problem still occurs.

Thanks!

Review Cisco Networking products for a $25 gift card