Cisco ASA Audit Event: 108007

108007: TLS started on ESMTP session between client and server

Cisco ASA is a security device that provides the combined capabilities of a firewall, an antivirus, and an intrusion prevention system. It also facilitates virtual private network (VPN) connections. It helps to detect threats and stop attacks before they spread through the network. 

Message: %ASA-6-108007: TLS started on ESMTP session between client client-side interface-name : client IP address /client port and server server-side interface-name: server IP address /server port

Event 108007 is generated when a server responds with a 220 reply code to the STARTTLS command by the client on an ESMTP command. The message contains:

  • The client-side interface name.
  • The client IP address and port number.
  • The server-side interface name.
  • The server IP address and port number.

How could you resolve this situation?

Check whether the ESMTP policy map associated with that connection has the allow-tls action log setting. If not, contact the Cisco TAC.

Cisco ASA Auditing Tool

EventLog Analyzer is a comprehensive log management software with which you can centrally collect, analyze, and manage logs from all the different log sources in your network. You also get reports and alerts on your network security, making it a power-packed IT security tool.