01-25-2017 06:45 PM - edited 03-12-2019 01:50 AM
Hello,
There are high around of ASA syslog related to ASA-4-313005 which also related to ICMP type3, code 3
------
Jan 26 10:36:04 192.168.10.2 %ASA-4-313005: No matching connection for ICMP error message: icmp src INSIDE:111.222.333.444 dst INSIDE:555.666.777.888 (type 3, code 3) on inside interface. Original IP payload: udp src 111.222.333.444/6343 dst 555.666.777.888/6343.
Jan 26 10:36:04 192.168.10.2 %ASA-4-313005: No matching connection for ICMP error message: icmp src outside:111.222.333.555 dst INSIDE:777.888.333.444 (type 3, code 3) on outside interface. Original IP payload: udp src 111.222.333.555/59851 dst 777.888.333.444/53.
Jan 26 10:36:04 192.168.10.2 %ASA-4-313005: No matching connection for ICMP error message: icmp src outside:555.666.777.888 dst INSIDE:123.123.123.123 (type 3, code 3) on outside interface. Original IP payload: udp src 123.123.123.123/59764 dst 555.666.777.888/53.
-----
Is it related to Black Nurse attack?
Thanks!
01-25-2017 09:28 PM
This looks like a genuine response for original packets sent across the ASA. For example:
Original IP payload: udp src 111.222.333.555/59851 dst 777.888.333.444/53.
The black nurse attack is usually originated from the outside to inside with a large stream.
Another indicator that this may not be an attack is the fact that the first message was between Inside to Inside interface. It's highly unlikely that an attack would occur from within the network (possible though). It would be good to investigate the inside host sending the packet in the place to see if this is a genuine packet.
01-25-2017 11:19 PM
Hi,
BlackNurse is based on ICMP with Type 3 Code 3 packets. So the above error which you posted is related to Black Nurse Attack.It's known also to cisco as DoS vulnerability with ICMP default implementation. Chick link below, hope it will help.
https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvc07227/?referring_site=s
Regards
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide