Cisco ASA Audit Event: 325004

325004: IPv6 extension header

Cisco ASA is a security device that provides the combined capabilities of a firewall, an antivirus, and an intrusion prevention system. It also facilitates virtual private network (VPN) connections. It helps to detect threats and stop attacks before they spread through the network.

Message: %ASA-4-325004: IPv6 Extension Header hdr_type action configuration.protocol from src_int :src_ipv6_addr /src_port to dst_interface: dst_ipv6_addr / dst_port.

Event 325004 is generated when a user has configured one or multiple actions over the specified IPv6 header extension. The message contains information on the:

  • HDR type.
  • Protocol.
  • Source interface name, IPv6 address, and port number.
  • Destination interface name, IPv6 address, and port number.
  • Action to be taken.

How could you resolve this situation?

If the configured action is not expected, under the 'policy-map' command, check the action in the 'match header extension_header_type' command and the 'parameters' command, and make the correct changes.

Cisco ASA Auditing Tool

EventLog Analyzer is a comprehensive log management software with which you can centrally collect, analyze, and manage logs from all the different log sources in your network. You also get reports and alerts on your network security, making it a power-packed IT security tool.