<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ASA 5510 logging ACL denies without &amp;quot;log&amp;quot; keyword with WARNING severity in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-asa-5510-logging-acl-denies-without-quot-log-quot-keyword/m-p/4060483#M1068902</link>
    <description>&lt;P&gt;Perfect, that was it. Thanks!&lt;/P&gt;</description>
    <pubDate>Tue, 07 Apr 2020 00:32:40 GMT</pubDate>
    <dc:creator>Sam Brynes</dc:creator>
    <dc:date>2020-04-07T00:32:40Z</dc:date>
    <item>
      <title>Cisco ASA 5510 logging ACL denies without "log" keyword with WARNING severity</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5510-logging-acl-denies-without-quot-log-quot-keyword/m-p/4059548#M1068803</link>
      <description>&lt;P&gt;I've enabled logging (logging enable) on our Cisco ASA 5510. I have an ACL on our outside interface. I see many deny log entries with a warning (level 4) severity, but I don't have the "log" keyword enabled on any of the ACL entries in the referenced ACL. Does anyone know where the warning (level 4) denies are coming from, and how I can stop them?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ASA5510(config)# sh run all | i logging&lt;BR /&gt;logging enable&lt;BR /&gt;logging timestamp&lt;BR /&gt;logging hide username&lt;BR /&gt;logging buffer-size 1048576&lt;BR /&gt;logging asdm-buffer-size 100&lt;BR /&gt;logging monitor notifications&lt;BR /&gt;logging buffered notifications&lt;BR /&gt;logging flash-minimum-free 3076&lt;BR /&gt;logging flash-maximum-allocation 1024&lt;BR /&gt;logging rate-limit 1 10 message 747001&lt;BR /&gt;logging rate-limit 1 1 message 402116&lt;BR /&gt;logging rate-limit 1 10 message 620002&lt;BR /&gt;logging rate-limit 1 10 message 717015&lt;BR /&gt;logging rate-limit 1 10 message 717018&lt;BR /&gt;logging rate-limit 1 10 message 201013&lt;BR /&gt;logging rate-limit 1 10 message 201012&lt;BR /&gt;logging rate-limit 1 1 message 313009&lt;BR /&gt;logging rate-limit 100 1 message 750003&lt;BR /&gt;logging rate-limit 100 1 message 750002&lt;BR /&gt;logging rate-limit 100 1 message 750004&lt;BR /&gt;logging rate-limit 1 10 message 419003&lt;BR /&gt;logging rate-limit 1 10 message 405002&lt;BR /&gt;logging rate-limit 1 10 message 405003&lt;BR /&gt;logging rate-limit 1 10 message 421007&lt;BR /&gt;logging rate-limit 1 10 message 405001&lt;BR /&gt;logging rate-limit 1 10 message 421001&lt;BR /&gt;logging rate-limit 1 10 message 421002&lt;BR /&gt;logging rate-limit 1 10 message 337004&lt;BR /&gt;logging rate-limit 1 10 message 337005&lt;BR /&gt;logging rate-limit 1 10 message 337001&lt;BR /&gt;logging rate-limit 1 10 message 337002&lt;BR /&gt;logging rate-limit 1 60 message 199020&lt;BR /&gt;logging rate-limit 1 10 message 337003&lt;BR /&gt;logging rate-limit 2 5 message 199011&lt;BR /&gt;logging rate-limit 1 10 message 199010&lt;BR /&gt;logging rate-limit 1 10 message 337009&lt;BR /&gt;logging rate-limit 2 5 message 199012&lt;BR /&gt;logging rate-limit 1 10 message 710002&lt;BR /&gt;logging rate-limit 1 10 message 209003&lt;BR /&gt;logging rate-limit 1 10 message 209004&lt;BR /&gt;logging rate-limit 1 10 message 209005&lt;BR /&gt;logging rate-limit 1 10 message 431002&lt;BR /&gt;logging rate-limit 1 10 message 431001&lt;BR /&gt;logging rate-limit 1 1 message 447001&lt;BR /&gt;logging rate-limit 1 10 message 110003&lt;BR /&gt;logging rate-limit 1 10 message 110002&lt;BR /&gt;logging rate-limit 1 10 message 429007&lt;BR /&gt;logging rate-limit 1 10 message 216004&lt;BR /&gt;logging rate-limit 1 10 message 450001&lt;BR /&gt;ASA5510(config)#&lt;BR /&gt;ASA5510(config)#sh logging&lt;BR /&gt;Syslog logging: enabled&lt;BR /&gt;Facility: 20&lt;BR /&gt;Timestamp logging: enabled&lt;BR /&gt;Hide Username logging: enabled&lt;BR /&gt;Standby logging: disabled&lt;BR /&gt;Debug-trace logging: disabled&lt;BR /&gt;Console logging: disabled&lt;BR /&gt;Monitor logging: level notifications, 891 messages logged&lt;BR /&gt;Buffer logging: level notifications, 884 messages logged&lt;BR /&gt;Trap logging: disabled&lt;BR /&gt;Permit-hostdown logging: disabled&lt;BR /&gt;History logging: disabled&lt;BR /&gt;Device ID: disabled&lt;BR /&gt;Mail logging: disabled&lt;BR /&gt;ASDM logging: disabled&lt;BR /&gt;ASA5510(config)#&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Deny examples:&lt;/P&gt;&lt;P&gt;Apr 05 2020 23:25:15: %ASA-4-106023: Deny udp src outside:168.232.213.153/21592 dst inside:172.18.0.4/10682 by access-group "ACL-OUTSIDE-IN" [0xe63c7008, 0x0]&lt;BR /&gt;Apr 05 2020 23:25:16: %ASA-4-106023: Deny udp src outside:178.198.131.51/40837 dst inside:172.18.0.4/10682 by access-group "ACL-OUTSIDE-IN" [0xe63c7008, 0x0]&lt;BR /&gt;Apr 05 2020 23:25:19: %ASA-4-106023: Deny udp src outside:178.198.131.51/40837 dst inside:172.18.0.4/10682 by access-group "ACL-OUTSIDE-IN" [0xe63c7008, 0x0]&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Our ACL:&lt;/P&gt;&lt;P&gt;ASA5510(config)# sh access-list ACL-OUTSIDE-IN&lt;BR /&gt;access-list ACL-OUTSIDE-IN; 11 elements; name hash: 0x4c51d238&lt;BR /&gt;access-list ACL-OUTSIDE-IN line 1 extended deny ip 10.0.0.0 255.0.0.0 any (hitcnt=15) 0x048a140c&lt;BR /&gt;access-list ACL-OUTSIDE-IN line 2 extended deny ip 172.16.0.0 255.240.0.0 any (hitcnt=109) 0xd408f2c1&lt;BR /&gt;access-list ACL-OUTSIDE-IN line 3 extended deny ip 192.168.0.0 255.255.0.0 any (hitcnt=0) 0x783f94e3&lt;BR /&gt;access-list ACL-OUTSIDE-IN line 4 extended deny ip 224.0.0.0 224.0.0.0 any (hitcnt=0) 0x9a833009&lt;BR /&gt;access-list ACL-OUTSIDE-IN line 6 extended permit icmp any any unreachable (hitcnt=100583) 0x6aeef44e&lt;BR /&gt;access-list ACL-OUTSIDE-IN line 7 extended permit icmp any any time-exceeded (hitcnt=6983) 0x4242299f&lt;BR /&gt;access-list ACL-OUTSIDE-IN line 8 extended deny icmp any any (hitcnt=0) 0x43e8b911&lt;BR /&gt;access-list ACL-OUTSIDE-IN line 9 extended deny udp any any (hitcnt=658) 0xe63c7008&lt;BR /&gt;access-list ACL-OUTSIDE-IN line 10 extended deny tcp any any (hitcnt=232) 0x783583f8&lt;BR /&gt;access-list ACL-OUTSIDE-IN line 11 extended deny ip any any (hitcnt=0) 0x320f194c&lt;BR /&gt;ASA5510(config)#&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Apr 2020 02:22:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5510-logging-acl-denies-without-quot-log-quot-keyword/m-p/4059548#M1068803</guid>
      <dc:creator>Sam Brynes</dc:creator>
      <dc:date>2020-04-06T02:22:16Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA 5510 logging ACL denies without "log" keyword with WARNING severity</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5510-logging-acl-denies-without-quot-log-quot-keyword/m-p/4060143#M1068882</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;The ASA firewall, by default, logs anytime there is an ACE match in your ACL for a new flow, with or without the "log" keyword being configured. If you don't specify the log keyword you get a "&lt;SPAN&gt;106023" system message, if you do&amp;nbsp;specify the log keyword you get a "106100" system message. If you&amp;nbsp;don't want the ASA to log at all, configure the ACE with the "log disable" option. Like for example:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;access-list ACL-OUTSIDE-IN line 9 extended deny udp any any log disable&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Cristian Matei.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Apr 2020 16:38:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5510-logging-acl-denies-without-quot-log-quot-keyword/m-p/4060143#M1068882</guid>
      <dc:creator>Cristian Matei</dc:creator>
      <dc:date>2020-04-06T16:38:12Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA 5510 logging ACL denies without "log" keyword with WARNING severity</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5510-logging-acl-denies-without-quot-log-quot-keyword/m-p/4060483#M1068902</link>
      <description>&lt;P&gt;Perfect, that was it. Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 07 Apr 2020 00:32:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5510-logging-acl-denies-without-quot-log-quot-keyword/m-p/4060483#M1068902</guid>
      <dc:creator>Sam Brynes</dc:creator>
      <dc:date>2020-04-07T00:32:40Z</dc:date>
    </item>
  </channel>
</rss>

