<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Make ASA debug commands persistent in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/make-asa-debug-commands-persistent/m-p/5031647#M1109557</link>
    <description>&lt;P&gt;Yes, this is the vpn which is to be debugged right now.&lt;/P&gt;
&lt;P&gt;Also a nice weekend for you!&lt;/P&gt;</description>
    <pubDate>Fri, 01 Mar 2024 12:11:28 GMT</pubDate>
    <dc:creator>lukasl1991</dc:creator>
    <dc:date>2024-03-01T12:11:28Z</dc:date>
    <item>
      <title>Make ASA debug commands persistent</title>
      <link>https://community.cisco.com/t5/network-security/make-asa-debug-commands-persistent/m-p/5031301#M1109544</link>
      <description>&lt;P&gt;Hello community,&lt;/P&gt;
&lt;P&gt;I refer to &lt;A href="https://community.cisco.com/t5/network-security/any-way-to-have-asa-quot-debug-quot-commands-stay-on/m-p/5029998" target="_self"&gt;this&lt;/A&gt; (quite old) discussion and this&amp;nbsp;&lt;A href="https://community.cisco.com/t5/network-security/any-way-to-have-asa-quot-debug-quot-commands-stay-on/m-p/4126974/highlight/true#M1072384" target="_self"&gt;answer&lt;/A&gt;&amp;nbsp;which is not that old... But I have an ASA with software version 9.9(2)80. I would like to send debug messages via syslog even after ssh logout.&lt;/P&gt;
&lt;P&gt;The answer tells that one should at first use&amp;nbsp;logging debug-trace persistent and afterwards the desired debug commands. This sould make the debug config persistent. I paste the example here again:&lt;/P&gt;
&lt;P&gt;debug aaa shim enabled at level 255&lt;BR /&gt;debug aaa shim enabled at level 255 (&lt;STRONG&gt;persistent&lt;/STRONG&gt;)&lt;BR /&gt;debug webvpn enabled at level 255&lt;BR /&gt;debug webvpn enabled at level 255 (&lt;STRONG&gt;persistent&lt;/STRONG&gt;)&lt;BR /&gt;debug webvpn xml enabled at level 255&lt;BR /&gt;debug webvpn xml enabled at level 255 (&lt;STRONG&gt;persistent&lt;/STRONG&gt;)&lt;BR /&gt;debug webvpn anyconnect enabled at level 255&lt;BR /&gt;debug webvpn anyconnect enabled at level 255 (&lt;STRONG&gt;persistent&lt;/STRONG&gt;)&lt;/P&gt;
&lt;P&gt;Regardless of the order of these two steps I cannot make debugging persistent. What am I doing wrong? Is that feature still working? I think logging debug-trace persistent&lt;SPAN class="HwtZe"&gt;&lt;SPAN class="jCAhz ChMk0b"&gt;&lt;SPAN class="ryNqvb"&gt;&amp;nbsp;is quite useless when all debuggers won't be persistent.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2024 07:49:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/make-asa-debug-commands-persistent/m-p/5031301#M1109544</guid>
      <dc:creator>lukasl1991</dc:creator>
      <dc:date>2024-03-01T07:49:57Z</dc:date>
    </item>
    <item>
      <title>Re: Make ASA debug commands persistent</title>
      <link>https://community.cisco.com/t5/network-security/make-asa-debug-commands-persistent/m-p/5031331#M1109545</link>
      <description>&lt;P&gt;You want to send debug ad syslog to server even if there is no ssh/telnet&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;logging debug-trace persistent &amp;lt;&amp;lt;- this command do that&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;But you need also to make log level 7&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Or&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Move the debug specific message to lower level like level 3 or 4 and config log level 3 or 4.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;MHM&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2024 08:06:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/make-asa-debug-commands-persistent/m-p/5031331#M1109545</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-03-01T08:06:36Z</dc:date>
    </item>
    <item>
      <title>Re: Make ASA debug commands persistent</title>
      <link>https://community.cisco.com/t5/network-security/make-asa-debug-commands-persistent/m-p/5031545#M1109548</link>
      <description>&lt;P&gt;Yes, this command is persistent over different ssh sessions. And I also have issued the&amp;nbsp;logging trap debug command. Now I have debug logs arriving on my syslog server.&lt;/P&gt;
&lt;P&gt;I'd like to use additional debug commands. Their output should then arrive as&amp;nbsp;&lt;SPAN&gt;%&lt;/SPAN&gt;&lt;SPAN class="ph"&gt;ASA&lt;/SPAN&gt;&lt;SPAN&gt;-7-711001: debug_trace_msg on my syslog server. (&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/syslog/b_syslog/syslog-messages-701001-to-714011.html" target="_blank"&gt;Cisco Secure Firewall ASA Series Syslog Messages - Syslog Messages 701001 to 714011 [Cisco Secure Firewall ASA] - Cisco&lt;/A&gt;)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;asa# show debug&lt;BR /&gt;debug crypto ipsec enabled at level 255&lt;BR /&gt;debug crypto ikev2 protocol enabled at level 255&lt;BR /&gt;debug crypto ikev2 platform enabled at level 255&lt;BR /&gt;debug crypto ike-common enabled at level 255&lt;/P&gt;
&lt;P&gt;Crypto conditional debug is turned ON&lt;/P&gt;
&lt;P&gt;IKE peer IP address filters:&lt;BR /&gt;A.B.C.D/32&lt;/P&gt;
&lt;P&gt;This also works. For example, I have the following line on my syslog server:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;%ASA-7-711001: IKEv2-PROTO-7: (14829): Restarting DPD timer 10 secs#012&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;When I now exit the ssh session, the debug crypto commands do not persist. (The only exception is the peer address.) T&lt;SPAN&gt;his&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://community.cisco.com/t5/network-security/any-way-to-have-asa-quot-debug-quot-commands-stay-on/m-p/4126974/highlight/true#M1072384" target="_self"&gt;answer&lt;/A&gt;&amp;nbsp;describes that also these debug lines should persist if they are issued AFTER&amp;nbsp;&lt;SPAN&gt;logging debug-trace persistent. This is what I've done. The ASA doesn't even show the suffix (persistent) in the show debug output before I quit the ssh.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2024 10:36:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/make-asa-debug-commands-persistent/m-p/5031545#M1109548</guid>
      <dc:creator>lukasl1991</dc:creator>
      <dc:date>2024-03-01T10:36:24Z</dc:date>
    </item>
    <item>
      <title>Re: Make ASA debug commands persistent</title>
      <link>https://community.cisco.com/t5/network-security/make-asa-debug-commands-persistent/m-p/5031546#M1109549</link>
      <description>&lt;P&gt;can I see logging config of asa&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2024 10:37:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/make-asa-debug-commands-persistent/m-p/5031546#M1109549</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-03-01T10:37:30Z</dc:date>
    </item>
    <item>
      <title>Re: Make ASA debug commands persistent</title>
      <link>https://community.cisco.com/t5/network-security/make-asa-debug-commands-persistent/m-p/5031548#M1109550</link>
      <description>&lt;P&gt;Syslog logging: enabled&lt;BR /&gt;Facility: 20&lt;BR /&gt;Timestamp logging: disabled&lt;BR /&gt;Hide Username logging: enabled&lt;BR /&gt;Standby logging: disabled&lt;BR /&gt;Debug-trace logging: enabled (persistent)&lt;BR /&gt;Console logging: disabled&lt;BR /&gt;Monitor logging: disabled&lt;BR /&gt;Buffer logging: level debugging, 3000777717 messages logged&lt;BR /&gt;Trap logging: level debugging, facility 20, 2399028060 messages logged&lt;BR /&gt;Logging to outside &amp;lt;syslogA&amp;gt;, UDP TX:7843971 errors: 2 dropped: 22&lt;BR /&gt;Logging to outside &amp;lt;syslogB&amp;gt;, UDP TX:909631 errors: 4 dropped: 19&lt;BR /&gt;Global TCP syslog stats::&lt;BR /&gt;NOT_PUTABLE: 0, ALL_CHANNEL_DOWN: 0&lt;BR /&gt;CHANNEL_FLAP_CNT: 0, SYSLOG_PKT_LOSS: 0&lt;BR /&gt;PARTIAL_REWRITE_CNT: 0&lt;BR /&gt;Permit-hostdown logging: disabled&lt;BR /&gt;History logging: disabled&lt;BR /&gt;Device ID: disabled&lt;BR /&gt;Mail logging: disabled&lt;BR /&gt;ASDM logging: disabled&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2024 10:39:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/make-asa-debug-commands-persistent/m-p/5031548#M1109550</guid>
      <dc:creator>lukasl1991</dc:creator>
      <dc:date>2024-03-01T10:39:09Z</dc:date>
    </item>
    <item>
      <title>Re: Make ASA debug commands persistent</title>
      <link>https://community.cisco.com/t5/network-security/make-asa-debug-commands-persistent/m-p/5031549#M1109551</link>
      <description>&lt;P&gt;Ok, now it magically works. No idea what the problem was. But nevertheless, the output is&amp;nbsp;&lt;/P&gt;
&lt;P&gt;debug crypto ipsec enabled at level 255&lt;BR /&gt;debug crypto ikev2 protocol enabled at level 255&lt;BR /&gt;debug crypto ikev2 platform enabled at level 255&lt;BR /&gt;debug crypto ike-common enabled at level 255&lt;/P&gt;
&lt;P&gt;Crypto conditional debug is turned ON&lt;/P&gt;
&lt;P&gt;IKE peer IP address filters:&lt;BR /&gt;&lt;SPAN&gt;A.B.C.D/32&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;without persistent in parentheses.&lt;/P&gt;
&lt;P&gt;And after you reconnct via ssh you only have this output:&lt;/P&gt;
&lt;P&gt;asa# sh debug&lt;/P&gt;
&lt;P&gt;Crypto conditional debug is turned ON&lt;/P&gt;
&lt;P&gt;IKE peer IP address filters:&lt;BR /&gt;&lt;SPAN&gt;A.B.C.D/32&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But thats ok for me as long as the syslog messages arrive. Thanks for your efforts!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2024 10:50:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/make-asa-debug-commands-persistent/m-p/5031549#M1109551</guid>
      <dc:creator>lukasl1991</dc:creator>
      <dc:date>2024-03-01T10:50:12Z</dc:date>
    </item>
    <item>
      <title>Re: Make ASA debug commands persistent</title>
      <link>https://community.cisco.com/t5/network-security/make-asa-debug-commands-persistent/m-p/5031618#M1109554</link>
      <description>&lt;P&gt;friend you are so welcome&amp;nbsp;&lt;BR /&gt;have a nice weekend&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2024 11:46:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/make-asa-debug-commands-persistent/m-p/5031618#M1109554</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-03-01T11:46:13Z</dc:date>
    </item>
    <item>
      <title>Re: Make ASA debug commands persistent</title>
      <link>https://community.cisco.com/t5/network-security/make-asa-debug-commands-persistent/m-p/5031641#M1109556</link>
      <description>&lt;P&gt;by the way the crypto conditional is ON and debug appear only for peer A.B.C.D/32 &amp;lt;&amp;lt;- if that what you want it OK if not disable condition to see debug for all peers and for all VPN&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2024 12:05:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/make-asa-debug-commands-persistent/m-p/5031641#M1109556</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-03-01T12:05:51Z</dc:date>
    </item>
    <item>
      <title>Re: Make ASA debug commands persistent</title>
      <link>https://community.cisco.com/t5/network-security/make-asa-debug-commands-persistent/m-p/5031647#M1109557</link>
      <description>&lt;P&gt;Yes, this is the vpn which is to be debugged right now.&lt;/P&gt;
&lt;P&gt;Also a nice weekend for you!&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2024 12:11:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/make-asa-debug-commands-persistent/m-p/5031647#M1109557</guid>
      <dc:creator>lukasl1991</dc:creator>
      <dc:date>2024-03-01T12:11:28Z</dc:date>
    </item>
  </channel>
</rss>

