Cisco ASA Audit Event: 201008

201008: Disallowing new connections

Cisco ASA is a security device that provides the combined capabilities of a firewall, an antivirus, and an intrusion prevention system. It also facilitates virtual private network (VPN) connections.It helps to detect threats and stop attacks before they spread through the network.

Message: %ASA-3-201008: Disallowing new connections.

Event 201008 could be generated on one of these scenarios:

  • TCP system log messaging is enabled and the syslog server cannot be reached.
  • The ASA syslog server is used and the disk on Windows NT system becomes full.
  • Auto-upgrade timeout is configured and the auto-update server is not reachable.

How could you resolve this situation?

Disable TCP syslog messaging. If using PFSS, free up space on the Windows NT system where PFSS resides. Make sure that the syslog server is up and you can ping the host from the ASA console. Then restart TCP system message logging to allow traffic.

Cisco ASA Auditing Tool

EventLog Analyzer is a comprehensive log management software with which you can centrally collect, analyze, and manage logs from all the different log sources in your network. You also get reports and alerts on your network security, making it a power-packed IT security tool.