Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements
Step-by-Step Configuration and Troubleshooting Best Practices for the NGFW, NGIPS and AMP Technologies A Visual Guide to the Cisco Firepower Threat Defense (FTD)
Community Member

Deny UDP reverse path check

We have a ASA up for a few years now and I am finally trying to understand some of the syslog info.  I configured it yesterday to email any Alerts and Emergency messages.  In the past 21 hrs I have received 511 (I'm glad I had conversation view enabled in Outlook).  I have many questions but I will start with why, throughout the night, I receive (over 100) something like this:

<185>Jan 18 2012 07:23:32: %ASA-1-106021: Deny UDP reverse path check from 169.254.146.189 to 198.41.0.4 on interface inside

Looks like a Windows client with a self assigned IP. We have an open wireless "guest" network for students to use for the smart phones, etc..., which is always out of IP addresses.    What is it trying to do? What is 198.41.0.4 (always different)?  If these are harmless, can I stop it from reporting them?

1 REPLY
Cisco Employee

Deny UDP reverse path check

Michael,

All syslogs ASA 8.3 are referenced here:

http://www.cisco.com/en/US/docs/security/asa/asa83/system/message/logmsgs.html

You can easily google for different version of this document.

As far as checking what that IP is. Best start by checking whois :-)

In this case it's verisign ... not sure why anyone would send UDP to it ... you might need to sniff traffic.

whois 198.41.0.4

#

# Query terms are ambiguous.  The query is assumed to be:

#     "n 198.41.0.4"

#

# Use "?" to get help.

#

#

# The following results may also be obtained via:

# http://whois.arin.net/rest/nets;q=198.41.0.4?showDetails=true&showARIN=false&ext=netref2

#

NetRange:       198.41.0.0 - 198.41.3.255

CIDR:           198.41.0.0/22

OriginAS:

NetName:        INTERNIC1

NetHandle:      NET-198-41-0-0-1

Parent:         NET-198-0-0-0-0

NetType:        Direct Assignment

RegDate:        1993-01-04

Updated:        2005-01-13

Ref:            http://whois.arin.net/rest/net/NET-198-41-0-0-1

OrgName:        VeriSign Infrastructure & Operations

OrgId:          VIO-2

Address:        12061 Bluemont Way

City:           Reston

StateProv:      VA

PostalCode:     20190

Country:        US

RegDate:        2002-07-11

Updated:        2012-01-03

Ref:            http://whois.arin.net/rest/org/VIO-2

OrgAbuseHandle: NETWO480-ARIN

OrgAbuseName:   Network Admin

OrgAbusePhone:  +1-703-948-4300

OrgAbuseEmail:  netadmin@verisign.com

OrgAbuseRef:    http://whois.arin.net/rest/poc/NETWO480-ARIN

OrgTechHandle: NETWO480-ARIN

OrgTechName:   Network Admin

OrgTechPhone:  +1-703-948-4300

OrgTechEmail:  netadmin@verisign.com

OrgTechRef:    http://whois.arin.net/rest/poc/NETWO480-ARIN

#

# ARIN WHOIS data and services are subject to the Terms of Use

# available at: https://www.arin.net/whois_tou.html

#

1792
Views
0
Helpful
1
Replies
CreatePlease to create content