<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Has the &amp;quot;internal ASA&amp;quot; NAT in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/transit-syslog-being-dropped/m-p/2914312#M157020</link>
    <description>&lt;P&gt;Has the "internal ASA" NAT configured?&lt;/P&gt;
&lt;P&gt;In that case a NAT-exemption could help.&lt;/P&gt;
&lt;P&gt;That's all I can think of with this little information.&lt;/P&gt;
&lt;P&gt;Rgds, MiKa&lt;/P&gt;</description>
    <pubDate>Tue, 12 Jul 2016 17:36:13 GMT</pubDate>
    <dc:creator>m.kafka</dc:creator>
    <dc:date>2016-07-12T17:36:13Z</dc:date>
    <item>
      <title>transit syslog being dropped</title>
      <link>https://community.cisco.com/t5/network-security/transit-syslog-being-dropped/m-p/2914311#M157019</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;here is our setup:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;syslog server &amp;lt;-&amp;gt; ASA Internal &amp;lt;-&amp;gt; ASA external&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Both ASA's are set to send syslog to the same IP address and the Internal works but the external does not. (Ping to syslog from both asa is working)&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;What I am seeing is using packet capture on ASA internal, on the interface facing external I can see syslog traffic being received (so this rules external asa out of the picture), however on the ASA internal interface facing syslog server no packets being captured.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have used packet tracer to simulate the traffic and it shows allowed and appropriate acl is configured (there is no outbound acl configured)&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I believe the issue may be due to the fact both ASA's are using 514 as their source port and destination port. I see no other reason for ASA Internal to drop the traffic which it clearly is doing. Is there any reason for ASA to drop traffic if source port are the same?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Can there be any other explanations for this?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;thanks!&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 08:00:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/transit-syslog-being-dropped/m-p/2914311#M157019</guid>
      <dc:creator>ryancisco01</dc:creator>
      <dc:date>2019-03-12T08:00:38Z</dc:date>
    </item>
    <item>
      <title>Has the "internal ASA" NAT</title>
      <link>https://community.cisco.com/t5/network-security/transit-syslog-being-dropped/m-p/2914312#M157020</link>
      <description>&lt;P&gt;Has the "internal ASA" NAT configured?&lt;/P&gt;
&lt;P&gt;In that case a NAT-exemption could help.&lt;/P&gt;
&lt;P&gt;That's all I can think of with this little information.&lt;/P&gt;
&lt;P&gt;Rgds, MiKa&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jul 2016 17:36:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/transit-syslog-being-dropped/m-p/2914312#M157020</guid>
      <dc:creator>m.kafka</dc:creator>
      <dc:date>2016-07-12T17:36:13Z</dc:date>
    </item>
  </channel>
</rss>

