<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco ASA logging issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-asa-logging-issue/m-p/4076879#M1069685</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;There is a strange issue, this cisco asa firewall is configured to send syslogs to an external server.&lt;/P&gt;&lt;P&gt;The firewall sends syslogs for few days and then suddenly there are no messages received on syslog server.&lt;/P&gt;&lt;P&gt;I have checked on the network level, everything is allowed and working.&lt;/P&gt;&lt;P&gt;Not sure what else to check now. Appreciate if someone can help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;Below is the configuration for logging-&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;logging enable&lt;BR /&gt;logging timestamp&lt;BR /&gt;logging standby&lt;BR /&gt;logging buffered informational&lt;BR /&gt;logging trap informational&lt;BR /&gt;logging asdm informational&lt;BR /&gt;logging device-id ipaddress outside&lt;BR /&gt;logging host outside xx.xx.xx.xx 17/10121&lt;BR /&gt;no logging message 313005&lt;BR /&gt;no logging message 607001&lt;BR /&gt;no logging message 302021&lt;BR /&gt;no logging message 302020&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;Output of show logging -&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;Syslog logging: enabled&lt;BR /&gt;Facility: 20&lt;BR /&gt;Timestamp logging: enabled&lt;BR /&gt;Hide Username logging: enabled&lt;BR /&gt;Standby logging: enabled&lt;BR /&gt;Debug-trace logging: disabled&lt;BR /&gt;Console logging: disabled&lt;BR /&gt;Monitor logging: disabled&lt;BR /&gt;Buffer logging: level informational, 242780794 messages logged&lt;BR /&gt;Trap logging: level informational, facility 20, 243580494 messages logged&lt;BR /&gt;Logging to outside xx.xx.xx.xx&amp;nbsp; udp/10121, UDP TX:12274&lt;BR /&gt;Global TCP syslog stats::&lt;BR /&gt;NOT_PUTABLE: 0, ALL_CHANNEL_DOWN: 0&lt;BR /&gt;CHANNEL_FLAP_CNT: 0, SYSLOG_PKT_LOSS: 0&lt;BR /&gt;PARTIAL_REWRITE_CNT: 0&lt;BR /&gt;Permit-hostdown logging: disabled&lt;BR /&gt;History logging: disabled&lt;BR /&gt;Device ID: 'outside' interface IP address "xx.xx.xx.xx"&lt;BR /&gt;Mail logging: disabled&lt;BR /&gt;ASDM logging: level informational, 242780794 messages logged&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;show logging queue&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;Logging Queue length limit : 512 msg(s)&lt;BR /&gt;0 msg(s) discarded due to queue overflow&lt;BR /&gt;0 msg(s) discarded due to memory allocation failure&lt;BR /&gt;Current 0 msg on queue, 251 msgs most on queue&lt;U&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One thing i have noticed, the UDP TX: count in the show logging output stays same for few minutes and is increased only by 1 or 2.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 30 Apr 2020 05:18:38 GMT</pubDate>
    <dc:creator>engineer467</dc:creator>
    <dc:date>2020-04-30T05:18:38Z</dc:date>
    <item>
      <title>Cisco ASA logging issue</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-logging-issue/m-p/4076879#M1069685</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;There is a strange issue, this cisco asa firewall is configured to send syslogs to an external server.&lt;/P&gt;&lt;P&gt;The firewall sends syslogs for few days and then suddenly there are no messages received on syslog server.&lt;/P&gt;&lt;P&gt;I have checked on the network level, everything is allowed and working.&lt;/P&gt;&lt;P&gt;Not sure what else to check now. Appreciate if someone can help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;Below is the configuration for logging-&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;logging enable&lt;BR /&gt;logging timestamp&lt;BR /&gt;logging standby&lt;BR /&gt;logging buffered informational&lt;BR /&gt;logging trap informational&lt;BR /&gt;logging asdm informational&lt;BR /&gt;logging device-id ipaddress outside&lt;BR /&gt;logging host outside xx.xx.xx.xx 17/10121&lt;BR /&gt;no logging message 313005&lt;BR /&gt;no logging message 607001&lt;BR /&gt;no logging message 302021&lt;BR /&gt;no logging message 302020&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;Output of show logging -&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;Syslog logging: enabled&lt;BR /&gt;Facility: 20&lt;BR /&gt;Timestamp logging: enabled&lt;BR /&gt;Hide Username logging: enabled&lt;BR /&gt;Standby logging: enabled&lt;BR /&gt;Debug-trace logging: disabled&lt;BR /&gt;Console logging: disabled&lt;BR /&gt;Monitor logging: disabled&lt;BR /&gt;Buffer logging: level informational, 242780794 messages logged&lt;BR /&gt;Trap logging: level informational, facility 20, 243580494 messages logged&lt;BR /&gt;Logging to outside xx.xx.xx.xx&amp;nbsp; udp/10121, UDP TX:12274&lt;BR /&gt;Global TCP syslog stats::&lt;BR /&gt;NOT_PUTABLE: 0, ALL_CHANNEL_DOWN: 0&lt;BR /&gt;CHANNEL_FLAP_CNT: 0, SYSLOG_PKT_LOSS: 0&lt;BR /&gt;PARTIAL_REWRITE_CNT: 0&lt;BR /&gt;Permit-hostdown logging: disabled&lt;BR /&gt;History logging: disabled&lt;BR /&gt;Device ID: 'outside' interface IP address "xx.xx.xx.xx"&lt;BR /&gt;Mail logging: disabled&lt;BR /&gt;ASDM logging: level informational, 242780794 messages logged&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;show logging queue&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;Logging Queue length limit : 512 msg(s)&lt;BR /&gt;0 msg(s) discarded due to queue overflow&lt;BR /&gt;0 msg(s) discarded due to memory allocation failure&lt;BR /&gt;Current 0 msg on queue, 251 msgs most on queue&lt;U&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One thing i have noticed, the UDP TX: count in the show logging output stays same for few minutes and is increased only by 1 or 2.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Apr 2020 05:18:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-logging-issue/m-p/4076879#M1069685</guid>
      <dc:creator>engineer467</dc:creator>
      <dc:date>2020-04-30T05:18:38Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA logging issue</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-logging-issue/m-p/4076891#M1069688</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;Check if your ACE (acl entry) are configured with 'log' keyword.&lt;BR /&gt;&lt;BR /&gt;e.g. access-list ACL-IN extended permit ip 192.168.1.0 255.255.255.0 host 8.8.8.8 log &amp;lt;---&lt;BR /&gt;&lt;BR /&gt;Confirm if UDP 514 are sending to remote logging server by 'packet capture'&lt;BR /&gt;&lt;BR /&gt;e.g.&lt;BR /&gt;&lt;BR /&gt;capture TEMP buff 2048 interface &amp;lt;EGRESS-INTERFAC-TO-SYSLOG-SVR&amp;gt; match udp host &amp;lt;ASA's IP&amp;gt; host &amp;lt;SYSLOG-SVR&amp;gt; eq 514&lt;BR /&gt;show capture TEMP&lt;BR /&gt;show capture TEMP&lt;BR /&gt;&amp;lt;.. check any packet fired out from ASA ..&amp;gt;&lt;BR /&gt;show capture TEMP&lt;BR /&gt;&amp;lt;...&amp;gt;&lt;BR /&gt;no capture TEMP</description>
      <pubDate>Thu, 30 Apr 2020 05:23:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-logging-issue/m-p/4076891#M1069688</guid>
      <dc:creator>ngkin2010</dc:creator>
      <dc:date>2020-04-30T05:23:06Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA logging issue</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-logging-issue/m-p/4076900#M1069689</link>
      <description>&lt;P&gt;Hello ngkin,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes logging is enabled on ACEs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;I entered the below command, replaced 514 with 10121-&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;capture TEMP buff 2048 interface &amp;lt;EGRESS-INTERFAC-TO-SYSLOG-SVR&amp;gt; match udp host &amp;lt;ASA's IP&amp;gt; host &amp;lt;SYSLOG-SVR&amp;gt; eq 10121&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Below is the output of packet capture-&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;8 packets captured&lt;/P&gt;&lt;P&gt;1: 11:22:44.980509 ASA's IP.514 &amp;gt; Syslog Server IP.10121: udp 199&lt;BR /&gt;2: 11:22:44.980524 ASA's IP.514 &amp;gt; Syslog Server IP..10121: udp 225&lt;BR /&gt;3: 11:22:46.909010 ASA's IP.514 &amp;gt; Syslog Server IP..10121: udp 200&lt;BR /&gt;4: 11:22:47.194127 ASA's IP.514 &amp;gt; Syslog Server IP..10121: udp 201&lt;BR /&gt;5: 11:22:47.269822 ASA's IP.514 &amp;gt; Syslog Server IP..10121: udp 202&lt;BR /&gt;6: 11:22:47.271729 ASA's IP.514 &amp;gt; Syslog Server IP..10121: udp 202&lt;BR /&gt;7: 11:22:47.363796 ASA's IP.514 &amp;gt; Syslog Server IP..10121: udp 159&lt;BR /&gt;8: 11:22:47.363811 ASA's IP.514 &amp;gt; Syslog Server IP..10121: udp 180&lt;BR /&gt;8 packets shown&lt;/P&gt;</description>
      <pubDate>Thu, 30 Apr 2020 05:44:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-logging-issue/m-p/4076900#M1069689</guid>
      <dc:creator>engineer467</dc:creator>
      <dc:date>2020-04-30T05:44:24Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA logging issue</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-logging-issue/m-p/4076907#M1069690</link>
      <description>&lt;P&gt;&lt;BR /&gt;Clearly, your ASA are sending SYSLOG message.&lt;BR /&gt;&lt;BR /&gt;You have to check if there is any routing issue in between ASA and SYSLOG server.&lt;BR /&gt;&lt;BR /&gt;Or if the packets were dropped by firewall.&lt;BR /&gt;&lt;BR /&gt;Also you are advised to confirm it's not an application layer issue. (e.g. check on SYSLOG server, confirm there is no incoming UDP:10121 message from the ASA) If it's a linux server, use "tcpdump -vvv -n 'host ASA-IP and port 10121' "&lt;/P&gt;</description>
      <pubDate>Thu, 30 Apr 2020 05:51:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-logging-issue/m-p/4076907#M1069690</guid>
      <dc:creator>ngkin2010</dc:creator>
      <dc:date>2020-04-30T05:51:21Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA logging issue</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-logging-issue/m-p/4076914#M1069693</link>
      <description>&lt;P&gt;Great help man, thank you.&lt;/P&gt;&lt;P&gt;There is another firewall in between our firewall and syslog server.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;firewall 1(outside interface)--&amp;gt;core sw--&amp;gt;(inside interface)firewall 2(outside interface)--&amp;gt;syslog server&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Hope the above explains the network setup.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is a firewall rule in firewall 2 allowing syslog traffic towards syslog server.&lt;/P&gt;&lt;P&gt;I ran a capture on firewall 2 on its inside interface, and I can see the syslog packets coming from firewall 1.&lt;/P&gt;&lt;P&gt;Then I ran another capture on its outside interface, but this time there are no packets captured.&lt;/P&gt;&lt;P&gt;Since the firewall rule is already in place allowing syslog traffic, what else could be the reason?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Apr 2020 06:17:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-logging-issue/m-p/4076914#M1069693</guid>
      <dc:creator>engineer467</dc:creator>
      <dc:date>2020-04-30T06:17:08Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA logging issue</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-logging-issue/m-p/4076915#M1069694</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;Is it a Cisco ASA? You may try to run 'packet tracer input &amp;lt;INGRESS-INTERFACE&amp;gt; udp &amp;lt;ASA-IP&amp;gt; 514 &amp;lt;SYSLOG-IP&amp;gt; 10121' to check if any reason that dropped by this firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You also could add "asp-drop" to view the dropped packet + dropped reason.&lt;/P&gt;&lt;PRE&gt;&lt;SPAN&gt;&lt;SPAN class="com"&gt;capture TEMP type asp-drop all&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Event viewer of ASDM also provide enough detail as well.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;There is a number of reason that would dropped by a firewall, hopefully the above commands could give you a proper reason to fix.&lt;BR /&gt;&lt;BR /&gt;Usually, it may be:&lt;BR /&gt;1. No policy allowed the connection&lt;BR /&gt;2. dropped due to Unicast Reverse Path Forwarding (uRPF)&lt;/P&gt;</description>
      <pubDate>Thu, 30 Apr 2020 06:38:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-logging-issue/m-p/4076915#M1069694</guid>
      <dc:creator>ngkin2010</dc:creator>
      <dc:date>2020-04-30T06:38:33Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA logging issue</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-logging-issue/m-p/4076922#M1069696</link>
      <description>&lt;P&gt;Its allowed as shown in packet tracer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Apr 2020 06:43:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-logging-issue/m-p/4076922#M1069696</guid>
      <dc:creator>engineer467</dc:creator>
      <dc:date>2020-04-30T06:43:02Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA logging issue</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-logging-issue/m-p/4076937#M1069698</link>
      <description>Try to confirm the packets are allowed with 'capture' command on egress interface.&lt;BR /&gt;&lt;BR /&gt;Try to confirm the connection is allowed according to log message on ASDM.&lt;BR /&gt;&lt;BR /&gt;Try to confirm the routing is correct (e.g. show route to check which egress interface used to reach SYSLOG server)&lt;BR /&gt;&lt;BR /&gt;Try to confirm if the packets are received by SYSLOG server or not (e.g. tcpdump as mentioned previously).&lt;BR /&gt;</description>
      <pubDate>Thu, 30 Apr 2020 06:57:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-logging-issue/m-p/4076937#M1069698</guid>
      <dc:creator>ngkin2010</dc:creator>
      <dc:date>2020-04-30T06:57:28Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA logging issue</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-logging-issue/m-p/4076950#M1069700</link>
      <description>&lt;P&gt;did a packet capture with asp drop-&lt;/P&gt;&lt;P&gt;capture temp type asp-drop all match udp host fw ip host sys ip eq 10121&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;got the below drop reason-&lt;/P&gt;&lt;P&gt;Drop-reason: (flow-expired) Expired flow&lt;/P&gt;</description>
      <pubDate>Thu, 30 Apr 2020 07:28:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-logging-issue/m-p/4076950#M1069700</guid>
      <dc:creator>engineer467</dc:creator>
      <dc:date>2020-04-30T07:28:03Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA logging issue</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-logging-issue/m-p/4076981#M1069704</link>
      <description>Oh...It become more complicated to find out the root cause.&lt;BR /&gt;&lt;BR /&gt;You may try to verify the existing flow by&lt;BR /&gt;'show conn protocol udp address &amp;lt;ASA-IP&amp;gt; port 514 address &amp;lt;SYSLOG-IP&amp;gt; port 10121 detail'&lt;BR /&gt;&lt;BR /&gt;Then try to clear the existing flow on ASA:&lt;BR /&gt;'clear conn protocol udp address &amp;lt;ASA-IP&amp;gt; port 514 address &amp;lt;SYSLOG-IP&amp;gt; port 10121'&lt;BR /&gt;&lt;BR /&gt;Afterward, do again with packet tracer&lt;BR /&gt;'packet tracer input &amp;lt;INGRESS-INTERFACE&amp;gt; udp &amp;lt;ASA-IP&amp;gt; 514 &amp;lt;SYSLOG-IP&amp;gt; 10121'&lt;BR /&gt;&lt;BR /&gt;And show it again, you should see a new session if there is new packet sent from your ASA:&lt;BR /&gt;'show conn protocol udp address &amp;lt;ASA-IP&amp;gt; port 514 address &amp;lt;SYSLOG-IP&amp;gt; port 10121 detail'&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;I am not quite sure the root cause, but I hope resetting the existing connection could help to address the issue. Kindly let us know your result.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 30 Apr 2020 08:31:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-logging-issue/m-p/4076981#M1069704</guid>
      <dc:creator>ngkin2010</dc:creator>
      <dc:date>2020-04-30T08:31:27Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA logging issue</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-logging-issue/m-p/4078328#M1069788</link>
      <description>&lt;P&gt;hello ngkin,&lt;/P&gt;&lt;P&gt;i ran captures, there was zero udp 10121 traffic on the egress interface. so i cleared the connections, also increased the udp timeout value.&lt;/P&gt;&lt;P&gt;The logs are sent to the syslog, now I will monitor if for few days to confirm if it was the udp timeout issue.&lt;/P&gt;&lt;P&gt;Not sure but lets see. I will update you anyways.&lt;/P&gt;&lt;P&gt;Thanks a lot for your help.&lt;/P&gt;</description>
      <pubDate>Sat, 02 May 2020 14:05:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-logging-issue/m-p/4078328#M1069788</guid>
      <dc:creator>engineer467</dc:creator>
      <dc:date>2020-05-02T14:05:32Z</dc:date>
    </item>
  </channel>
</rss>

