Cisco ASA Audit Event: 302017

302017: Built GRE connection

Cisco ASA is a security device that provides the combined capabilities of a firewall, an antivirus, and an intrusion prevention system. It also facilitates virtual private network (VPN) connections. It helps to detect threats and stop attacks before they spread through the network.

Message: %ASA-6-302017: Built {inbound|outbound} GRE connection id from interface :real_address (translated_address) [(idfw_user)] to interface:real_address /real_cid (translated_address /translated_cid) [(idfw_user)] [(user)].

Event 302017 is generated when a GRE connection slot is created between two hosts. The message contains information on the:

  • Connection identifier.
  • Control connection for inbound and outbound PPTP GRE flow.
  • Interface name.
  • IP address of the actual host.
  • Untranslated call ID for the connection.
  • IP address after translation.
  • Translated call.
  • AAA user name.
  • Name of the identity firewall user.

How could you resolve this situation?

This event does not require any action.

Cisco ASA Auditing Tool

EventLog Analyzer is a comprehensive log management software with which you can centrally collect, analyze, and manage logs from all the different log sources in your network. You also get reports and alerts on your network security, making it a power-packed IT security tool.