Re: Cisco ASA log anomaly (was Wireshark output.)

Jay Hennigan <[email protected]>
Newsgroups gmane.org.operators.internet-access
Message-ID <[email protected]>
Keith wrote:
> Wondering if someone can explain a network sniff that me and another
> fellow did this morning.
> 
> He has an ASA connected to our 3560. I am going to use a fake IP for his
> ASA.
> 
> So his ASA is on a Vlan. His ASA outside IP is 192.168.191.33/27. The
> inside IP on the ASA is 10.2.1.1/24.
> 
> Behind the ASA is another machine on 10.2.1.40.
> 
> He is seeing traffic on his ASA that concerns him.
> 
> Log from the ASA:
> 
> Built outbound TCP connection for outside IP of 10.10.10.26 to inside IP
> of 10.2.1.40.
> 
> The next entry is that the ASA tears down the TCP connection.
> 
> He does not have anything on 10.10.10.26 network at all.

Does he have a static from anything to 10.10.10.26 ?  Does 10.10.01.26 
appear in the config at all, and if so in what context?


--
Jay Hennigan - CCIE #7880 - Network Engineering - [email protected]
Impulse Internet Service  -  http://www.impulse.net/
Your local telephone and internet company - 805 884-6323 - WB6RDV
-- 
Eat sushi frequently. - Avi
[email protected] is the human contact address.
[email protected] is the list posting address.
See below URL for subscribe/unsubscribe and list options:
http://inet-access.net/mailman/listinfo/list
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.