Re: [loganalysis] Cisco ICMP logs

From: Mike Hogsett (hogsettat_private)
Date: Mon Aug 13 2001 - 15:10:16 PDT

  • Next message: Tina Bird: "Re: [loganalysis] Re: Central syslog server best practices?"

    For starters see : 
    
    http://www.iana.org/assignments/icmp-parameters
    
    Then refer to the RFC's listed as references.
    
    The first line is Destination Unreachable (3) / Host Unreachable (1)
    The second line is Time Exceeded (11) / TTL Exceeded (0)            
    
     - Mike Hogsett
    
    > 
    > 
    > I am trying to make some sense of a Cisco Router logs. In particular ICMP log
    > s,
    > does anyone know how to differentiate between different ICMP packet logs
    > recorded by the router. I am thinking that  (digit/digit) field has to do
    > somthing with the ICMP message type but I am not sure.
    > 
    > e.g.
    > 
    > Dec  8 16:07:45 <ciscorouter> 3128095: Dec  8 16:07:44: %SEC-6-IPACCESSLOGDP:
    >  list 104 denied icmp xxx.yyy.201.225 -> abc.def.64.77 (3/1), 1 packet
    > 
    > Dec  8 16:07:45 <ciscorouter> 3128095: Dec  8 16:07:44: %SEC-6-IPACCESSLOGDP:
    >  list 104 denied icmp xxx.yyy.201.225 -> abc.def.64.77 (11/0), 1 packet
    > 
    > 
    > Thanks
    >      Jas
    > 
    > 
    > 
    > 
    > -----------------------------------------------
    > ABS Australian Business Number:  26 331 428 522     ABS Web Site:  www.abs.go
    > v.au
    > 
    > ---------------------------------------------------------------------
    > To unsubscribe, e-mail: loganalysis-unsubscribeat_private
    > For additional commands, e-mail: loganalysis-helpat_private
    
    ---------------------------------------------------------------------
    To unsubscribe, e-mail: loganalysis-unsubscribeat_private
    For additional commands, e-mail: loganalysis-helpat_private
    



    This archive was generated by hypermail 2b30 : Tue Aug 14 2001 - 14:22:53 PDT