Not seeing ASA traffic even though it is in the logs
Issue: I download a 5GB file but Firewall Analyzer wont see it.
ASA: 5510 running v7.0 software
1. I can see the logs in Firewall Analyzer. I go to:
C:\AdventNet\ME\Firewall\server\default\archive\192.168.0.253\
and looking inside these logs, I can see two sessions for the 5GB download:
<166>Sep 04 2008 18:36:11 192.168.0.253 : %ASA-6-302014: Teardown TCP connection 4292886 for outside:72.247.247.83/80 to inside:192.168.0.2/3562 duration 4:17:51 bytes 971017632 TCP FINs
<166>Sep 05 2008 02:17:40 192.168.0.253 : %ASA-6-302014: Teardown TCP connection 4292634 for outside:72.247.247.83/80 to inside:192.168.0.2/3531 duration 12:00:10 bytes 3538878775 TCP FINs
2. Why doesn't Firewall Analyze understand these lines?? Why doesn't it show up when I look at traffic stats for 04/09/2008??
And when I do an advanced search on 192.168.0.2, it does not show this traffic.
3. I have uploaded the logs 2008_09_04_16_27_47 - 7MB file from Firewall Analyzer.
Assistance would be appreciated.
New to ADSelfService Plus?