<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA5508 syslog issue - classes session vs auth/webvpn events in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa5508-syslog-issue-classes-session-vs-auth-webvpn-events/m-p/5085486#M1111957</link>
    <description>&lt;P&gt;To be honest I dont get class session you use?&lt;/P&gt;
&lt;P&gt;Maybe more elaborate&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks alot&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
    <pubDate>Wed, 01 May 2024 08:00:39 GMT</pubDate>
    <dc:creator>MHM Cisco World</dc:creator>
    <dc:date>2024-05-01T08:00:39Z</dc:date>
    <item>
      <title>ASA5508 syslog issue - classes session vs auth/webvpn events</title>
      <link>https://community.cisco.com/t5/network-security/asa5508-syslog-issue-classes-session-vs-auth-webvpn-events/m-p/5081705#M1111793</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;I need to export all events from level informational from an ASA5508 to a syslog server. Basically, I set it as "logging trap informational"&lt;/P&gt;&lt;P&gt;This device provides firewall services as well as remote SSL VPN access and WebVPN.&lt;/P&gt;&lt;P&gt;I noticed that AAA and WebVPN events were not loggued.&lt;/P&gt;&lt;P&gt;After having few tests, I found that events from class session are mutually exclusive from almost all others classes and at least both classes auth and webvpn.&lt;/P&gt;&lt;P&gt;If I set a logging list containing all classes at informational level excluding the class session, it works fine. As soon I add the class session (even limited to level notification), I loose events from classes auth and webvpn.&lt;/P&gt;&lt;P&gt;I checked the default rate limit configuration. Messages I'm expecting are not rate limited.&lt;/P&gt;&lt;P&gt;I also checked default level bound to specific message I expect. It is informational :&lt;/P&gt;&lt;PRE&gt;asa# sh logging message 113015&lt;BR /&gt;syslog 113015: default-level informational (enabled),standby logging (disabled)&lt;BR /&gt;asa# sh logging message 716039&lt;BR /&gt;syslog 716039: default-level informational (enabled),standby logging (disabled)&lt;/PRE&gt;&lt;P&gt;I'm interested in logging all events but three classes are really mandatory :&lt;/P&gt;&lt;P&gt;* auth + webvpn to track VPN events&lt;/P&gt;&lt;P&gt;* session to track traffic&lt;/P&gt;&lt;P&gt;I have three platforms ASA5525X with same VPN features where this syslog setup works fine for classes session, auth and webvpn at same time.&lt;/P&gt;&lt;P&gt;By reading ASA syslog documentation, I do not find any information about this issue.&lt;/P&gt;&lt;P&gt;The issue was seen on version 9.16(4)42. The device has been updated to version 9.16(4)57.&lt;/P&gt;&lt;P&gt;Is it a known limitation of this platform 5508 ? or a bug ?&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2024 08:24:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5508-syslog-issue-classes-session-vs-auth-webvpn-events/m-p/5081705#M1111793</guid>
      <dc:creator>Jerome BERTHIER</dc:creator>
      <dc:date>2024-04-29T08:24:54Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5508 syslog issue - classes session vs auth/webvpn events</title>
      <link>https://community.cisco.com/t5/network-security/asa5508-syslog-issue-classes-session-vs-auth-webvpn-events/m-p/5084504#M1111933</link>
      <description>&lt;P&gt;Well not much people inspired by my question &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Finally, I think I found a good clue in the syslog documentation of version 9.16 :&lt;/P&gt;&lt;PRE&gt;When you configure syslog logging on an interface with management-only access enabled, the dataplane related logs (syslog IDs 302015, 302014, 106023, and 304001) are dropped and does not reach the syslog server. The syslog messages are dropped because the datapath routing table does not have the management interface routing. Hence, ensure the interface that you are configuring has management-only access disabled&lt;/PRE&gt;&lt;P class=""&gt;Those message IDs starting with 302 and 106 are from the class session. In my case, they are exported but not messages from other classes.&lt;/P&gt;&lt;P class=""&gt;As I do use the management interface, I think that even if these logs are not dropped then may move to CPU processing and impact others classes of logs.&lt;/P&gt;&lt;P class=""&gt;My next point will be to try to export logs from a revenue interface.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Apr 2024 16:03:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5508-syslog-issue-classes-session-vs-auth-webvpn-events/m-p/5084504#M1111933</guid>
      <dc:creator>Jerome BERTHIER</dc:creator>
      <dc:date>2024-04-30T16:03:54Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5508 syslog issue - classes session vs auth/webvpn events</title>
      <link>https://community.cisco.com/t5/network-security/asa5508-syslog-issue-classes-session-vs-auth-webvpn-events/m-p/5085486#M1111957</link>
      <description>&lt;P&gt;To be honest I dont get class session you use?&lt;/P&gt;
&lt;P&gt;Maybe more elaborate&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks alot&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 01 May 2024 08:00:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5508-syslog-issue-classes-session-vs-auth-webvpn-events/m-p/5085486#M1111957</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-05-01T08:00:39Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5508 syslog issue - classes session vs auth/webvpn events</title>
      <link>https://community.cisco.com/t5/network-security/asa5508-syslog-issue-classes-session-vs-auth-webvpn-events/m-p/5087086#M1111997</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;To be more accurate, below the typical setup I use on other ASA VPN devices :&lt;/P&gt;&lt;PRE&gt;logging enable&lt;BR /&gt;logging timestamp&lt;BR /&gt;no logging hide username&lt;BR /&gt;logging list my-events-list level informational class auth&lt;BR /&gt;logging list my-events-list level informational class config&lt;BR /&gt;logging list my-events-list level informational class ha&lt;BR /&gt;logging list my-events-list level informational class ids&lt;BR /&gt;logging list my-events-list level notifications class ip&lt;BR /&gt;logging list my-events-list level informational class np&lt;BR /&gt;logging list my-events-list level informational class rm&lt;BR /&gt;&lt;STRONG&gt;logging list my-events-list level notifications class session&lt;/STRONG&gt;&lt;BR /&gt;logging list my-events-list level informational class snmp&lt;BR /&gt;logging list my-events-list level informational class sys&lt;BR /&gt;logging list my-events-list level informational class vpdn&lt;BR /&gt;logging list my-events-list level informational class vpn&lt;BR /&gt;logging list my-events-list level informational class vpnc&lt;BR /&gt;logging list my-events-list level informational class vpnfo&lt;BR /&gt;logging list my-events-list level informational class vpnlb&lt;BR /&gt;logging list my-events-list level informational class webfo&lt;BR /&gt;logging list my-events-list level informational class webvpn&lt;BR /&gt;logging list my-events-list level informational class ca&lt;BR /&gt;logging list my-events-list level informational class svc&lt;BR /&gt;logging list my-events-list level informational class csd&lt;BR /&gt;logging list my-events-list level notifications class ssl&lt;BR /&gt;logging list my-events-list level informational class vm&lt;BR /&gt;logging list my-events-list level informational class dap&lt;BR /&gt;logging list my-events-list level warnings class ipaa&lt;BR /&gt;logging list my-events-list level informational class rule-engine&lt;BR /&gt;logging buffer-size 16384&lt;BR /&gt;logging buffered debugging&lt;BR /&gt;logging trap my-events-list&lt;BR /&gt;logging asdm notifications&lt;BR /&gt;logging device-id hostname&lt;BR /&gt;logging host management x.x.x.x&lt;/PRE&gt;&lt;P&gt;This setup works as expected on ASA5525X (for more a decade).&lt;/P&gt;&lt;P&gt;The same setup doesn't work on the single ASA5508 I have.&lt;/P&gt;&lt;P&gt;On this ASA5508, if the messages class "session" is used the other classes are not sent to external syslog server.&lt;/P&gt;&lt;P&gt;If I set to send all messages to syslog from level informational (logging trap informational), it doesn't work either. Same issue.&lt;/P&gt;&lt;P&gt;If I keep all classes in the setup except the class "session", it works then as soon I add the class "session", the device stops sending messages from other classes after a delay around 60 secondes (not measured accuratly).&lt;/P&gt;&lt;P&gt;As pointed out in my previous answer, I'm going to investigate on changing the source interface of the syslog export. I'll switch it to a dataplane port.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2024 06:39:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5508-syslog-issue-classes-session-vs-auth-webvpn-events/m-p/5087086#M1111997</guid>
      <dc:creator>Jerome BERTHIER</dc:creator>
      <dc:date>2024-05-02T06:39:17Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5508 syslog issue - classes session vs auth/webvpn events</title>
      <link>https://community.cisco.com/t5/network-security/asa5508-syslog-issue-classes-session-vs-auth-webvpn-events/m-p/5087299#M1112011</link>
      <description>&lt;P&gt;I solved the issue by moving syslog export from a dataplane interface.&lt;/P&gt;&lt;P&gt;The documentation is not accurate. I faced the opposite effect.&lt;/P&gt;&lt;P&gt;The documentation states :&lt;/P&gt;&lt;PRE&gt;When you configure syslog logging on an interface with management-only access enabled, the dataplane related logs (syslog IDs 302015, 302014, 106023, and 304001) are dropped and does not reach the syslog server. The syslog messages are dropped because the datapath routing table does not have the management interface routing.&lt;/PRE&gt;&lt;P&gt;It is the opposite. Messages are dropped except those from dataplane related logs.&lt;/P&gt;&lt;P&gt;By choosing to export logs from&amp;nbsp; a dataplane, you can retreive all types all logs.&lt;/P&gt;&lt;P&gt;Here, the simpliest final setup :&lt;/P&gt;&lt;PRE&gt;route &amp;lt;dataplane_interface&amp;gt; &amp;lt;syslog_IP&amp;gt; 255.255.255.255 &amp;lt;gw&amp;gt;&lt;BR /&gt;logging host &amp;lt;dataplane_interface&amp;gt; &amp;lt;syslog_IP&amp;gt;&lt;BR /&gt;&lt;BR /&gt;logging trap informational&lt;/PRE&gt;&lt;P&gt;As I said, this issue is seen on ASA5508 version 9.16(4).x but not on ASA5525X version 9.12(4).x.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2024 08:25:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5508-syslog-issue-classes-session-vs-auth-webvpn-events/m-p/5087299#M1112011</guid>
      <dc:creator>Jerome BERTHIER</dc:creator>
      <dc:date>2024-05-02T08:25:29Z</dc:date>
    </item>
  </channel>
</rss>

