Re: Cisco ASA log anomaly (was Wireshark output.)
Jay Hennigan <[email protected]>
| Newsgroups | gmane.org.operators.internet-access |
|---|---|
| Message-ID | <[email protected]> |
Keith wrote: > Wondering if someone can explain a network sniff that me and another > fellow did this morning. > > He has an ASA connected to our 3560. I am going to use a fake IP for his > ASA. > > So his ASA is on a Vlan. His ASA outside IP is 192.168.191.33/27. The > inside IP on the ASA is 10.2.1.1/24. > > Behind the ASA is another machine on 10.2.1.40. > > He is seeing traffic on his ASA that concerns him. > > Log from the ASA: > > Built outbound TCP connection for outside IP of 10.10.10.26 to inside IP > of 10.2.1.40. > > The next entry is that the ASA tears down the TCP connection. > > He does not have anything on 10.10.10.26 network at all. Does he have a static from anything to 10.10.10.26 ? Does 10.10.01.26 appear in the config at all, and if so in what context? -- Jay Hennigan - CCIE #7880 - Network Engineering - [email protected] Impulse Internet Service - http://www.impulse.net/ Your local telephone and internet company - 805 884-6323 - WB6RDV -- Eat sushi frequently. - Avi [email protected] is the human contact address. [email protected] is the list posting address. See below URL for subscribe/unsubscribe and list options: http://inet-access.net/mailman/listinfo/list