Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

PIX/ASA Connection Duration Logging and Reporting

I need to review and analyze connections which are maintained over a certain time period. I cannot get this in a legible format from the PIX/ASA directly during the activity with scalability, so the best I think I can do is look at it after the fact.

So what I have are the teardown messages from the PIX/ASA products in our MARS appliance.

Messages which have this info are like these 302016 and 302014.

May 29 2009 10:43:37: %PIX-6-302014: Teardown TCP connection 543470 for outside:1.2.3.4/3136 to inside:7.8.9.10/80 duration 0:02:04 bytes 1121 TCP FINs

May 29 2009 10:43:33: %PIX-6-302016: Teardown UDP connection 543463 for outside:1.2.3.4/1079 to inside:7.8.9.10/80 duration 0:02:01 bytes 454

Note: Addresses and/or ports listed above may have been changed.

Sometimes we have TCP and UDP connections which last for days. I have no real good way to report on the lengthy ones. Yet.

Can MARS analyze the PIX/ASA 302016 and 302014 messages for values after the “duration” string which may be greater than say 10 hours and create an event, another event for durations greater than say 5 days? Can some be created into low incidents?

If so, can you give me the keywords necessary to look this up in the MARS manuals myself? Also, I am not a coder/scripter and if good regex ability is needed, if you know of a good self help tutorial on the web you can refer me to, that would be good as well.

Thanks.

  • MARS
3 REPLIES
New Member

Re: PIX/ASA Connection Duration Logging and Reporting

A TCP connection between two hosts was deleted. And A UDP connection slot between two hosts was also deleted. That's why you are getting this log.

Force termination after two minutes awaiting three-way handshake completion.

http://www.cisco.com/en/US/docs/security/pix/pix63/system/message/pixemsgs.html#wp1054165

New Member

Re: PIX/ASA Connection Duration Logging and Reporting

? I'm not wondering why these messages are occurring.

I'm not seeking to break connections, I'm seeking a report of connections which meet a certain criteria.

I'm wanting to know which ones have a duration value greater than certain amounts, like 10 hours for example.

New Member

Re: PIX/ASA Connection Duration Logging and Reporting

Bump.

Anyone?

1183
Views
0
Helpful
3
Replies
This widget could not be displayed.