# Reversing of src/dst ip and port in cisco fwpattern file

**URL:** <https://discuss.elastic.co/t/reversing-of-src-dst-ip-and-port-in-cisco-fwpattern-file/64106>\
**Category:** Logstash\
**Created:** [October 27, 2016, 7:44am UTC](https://discuss.elastic.co/t/reversing-of-src-dst-ip-and-port-in-cisco-fwpattern-file/64106 "2016-10-27T07:44:52Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![ssi](https://avatars.discourse-cdn.com/v4/letter/s/a3d4f5/32.png) [@ssi](https://discuss.elastic.co/u/ssi)\
**Post date:** [October 27, 2016, 7:44am UTC](https://discuss.elastic.co/t/reversing-of-src-dst-ip-and-port-in-cisco-fwpattern-file/64106/1 "2016-10-27T07:44:52Z")

</div>

Hi I've noticed what i consider an error in the logstash firewall pattern related to cisco asa.

the syslogID in the cisco firewall raw log looks like this with respective relevant fields. We are testing opendns so DNS traffic from our network looks like this.

\<174\>%ASA-6-302015: Built **outbound** UDP connection 276686124 for OUTSIDE:208.67.222.222/53 (208.67.222.222/53) to INSIDE:172.xx.xx.11/59804 ([xxx.xxx.xxx.xxx/53723](http://xxx.xxx.xxx.xxx/53723))

This our inside dns server makeing a request to an outside (openDNS) server on port 53.

however looking at it in ELK it looks like this, and in my view making in look like the traffic is INBOUND, and thus reversed compared to what the ciscolog shows.

I believe the problem is in this part of the ciscoasa filter for logstash

/patterns/firewalls

# ASA-6-302013, ASA-6-302014, ASA-6-302015, ASA-6-302016

CISCOFW302013\_302014\_302015\_302016 %{CISCO\_ACTION:action}(?: %{CISCO\_DIRECTION:direction})? %{WORD:protocol} connection %{INT:connection\_id} for %{DATA:src\_interface}:%{IP:src\_ip}/%{INT:src\_port}( (%{IP:src\_mapped\_ip}/%{INT:src\_mapped\_port}))?((%{DATA:src\_fwuser}))? to %{DATA:dst\_interface}:%{IP:dst\_ip}/%{INT:dst\_port}( (%{IP:dst\_mapped\_ip}/%{INT:dst\_mapped\_port}))?((%{DATA:dst\_fwuser}))?( duration %{TIME:duration} bytes %{INT:bytes})?(?: %{CISCO\_REASON:reason})?( (%{DATA:user}))?

could be be that it can't handle the difference between inbound and outbound traffic, and there is a need for a filter that takes inbound/outbound into account?

in kibana after being parsed with logstash it looks like this

"direction": "outbound",  
"protocol": "UDP",  
"connection\_id": "276715487",  
"src\_interface": "OUTSIDE",  
**"src\_ip": "208.67.222.222",**  
**"src\_port": "53",**  
"src\_mapped\_ip": "208.67.222.222",  
"src\_mapped\_port": "53",  
"dst\_interface": "INSIDE",  
**"\_dst\_ip": "172.17.20.10",** \_  
**"dst\_port": "62110",**  
"dst\_mapped\_ip": "[xxx.xx.xxx.xxx](http://xxx.xx.xxx.xxx)",  
"dst\_mapped\_port": "62110",  
"syslog\_severity\_code": 5,  
"syslog\_facility\_code": 1,  
"syslog\_facility": "user-level",  
"syslog\_severity": "notice",  
"geoip": {  
"ip": "208.67.222.222",

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:32am UTC](https://discuss.elastic.co/t/reversing-of-src-dst-ip-and-port-in-cisco-fwpattern-file/64106/2 "2017-07-06T04:32:27Z")

</div>


