ASA 5520 dropped some packet from inside interface, Please help

Hello,

ASA 5520 dropped some packet from inside interface, I enabled logging to Pix syslog server. it seems the logging doesn't work. enable logging monitor dor telnet session, it doesn't show any. I need help for how to enable and read syslog, please. I download Cisco syslog server 5.1 for windows, the service is up, however, PFSS.log file never changes after I installed. Any suggestion?

Syslog logging: enabled Facility: 20 Timestamp logging: enabled Standby logging: disabled Deny Conn when Queue Full: disabled Console logging: disabled Monitor logging: level debugging, 8491 messages logged Buffer logging: disabled Trap logging: level errors, facility 20, 7 messages logged Logging to inside 10.105.34.20 History logging: disabled Device ID: disabled Mail logging: disabled ASDM logging: level informational, 5785 messages logged

Interface GigabitEthernet0/1 "inside", is up, line protocol is up Hardware is i82546GB rev03, BW 1000 Mbps Auto-Duplex(Full-duplex), Auto-Speed(1000 Mbps) MAC address 001a.6234.8bb5, MTU 1500 IP address 10.105.34.1, subnet mask 255.255.255.0 62927 packets input, 9537837 bytes, 0 no buffer Received 24417 broadcasts, 0 runts, 0 giants 0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort 0 L2 decode drops 45350 packets output, 3883857 bytes, 0 underruns 0 output errors, 0 collisions 0 late collisions, 0 deferred input queue (curr/max blocks): hardware (0/0) software (0/0) output queue (curr/max blocks): hardware (0/6) software (0/0) Traffic Statistics for "inside": 62927 packets input, 8369675 bytes 45350 packets output, 2843589 bytes 22709 packets dropped 1 minute input rate 6 pkts/sec, 522 bytes/sec 1 minute output rate 4 pkts/sec, 323 bytes/sec 1 minute drop rate, 2 pkts/sec 5 minute input rate 4 pkts/sec, 801 bytes/sec 5 minute output rate 3 pkts/sec, 273 bytes/sec 5 minute drop rate, 2 pkts/sec

Why there are so many packets dropped from inside interface?

Please help.

Reply to
UBEST
Loading thread data ...

Do you have a firewall on host 10.105.34.20, also can you ping the host? I get the syslog working then see the logfiles.

Also I would bump the syslog level up to 7 for this type of debugging

# logging trap 7 # exit # Wri mem

Reply to
Smokey

Reply to
UBEST

OK. I have made the syslog service up. there is udp default 514 conflict. syslog pops up and working.

Here are majority of logging:

167>Apr 25 2007 21:20:06: %ASA-7-710005: UDP request discarded from 0.0.0.0/68 to outside:255.255.255.255/67

Apr 25 2007 21:20:09: %ASA-7-710005: UDP request discarded from

0.0.0.0/68 to outside:255.255.255.255/67

Apr 25 2007 21:20:11: %ASA-7-710005: UDP request discarded from

0.0.0.0/68 to inside:255.255.255.255/67

Apr 25 2007 21:20:12: %ASA-7-710005: UDP request discarded from

0.0.0.0/68 to outside:255.255.255.255/67

Apr 25 2007 21:20:14: %ASA-7-710005: UDP request discarded from

0.0.0.0/68 to inside:255.255.255.255/67

Apr 25 2007 21:20:17: %ASA-7-710005: UDP request discarded from

0.0.0.0/68 to inside:255.255.255.255/67

Apr 25 2007 21:20:24: %ASA-7-710005: UDP request discarded from

0.0.0.0/68 to outside:255.255.255.255/67

Apr 25 2007 21:20:27: %ASA-7-710005: UDP request discarded from

0.0.0.0/68 to outside:255.255.255.255/67

UDP 68 is bootstrap or DHCP client request. we don't use any DHCP client inside of FW. How can I avoid such traffic?

Reply to
UBEST

Cabling-Design.com Forums website is not affiliated with any of the manufacturers or service providers discussed here. All logos and trade names are the property of their respective owners.