<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Firewall Email Alert config in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firewall-email-alert-config/m-p/2835575#M165957</link>
    <description>&lt;P&gt;We have one outside interface connection to ISP. The ISP wanted to do some maintaince work and informed us the link will do down for half and hour. therefore I configured the email alert on our production network where is configured the IPSLA with syslog, SMTP and with email address could verify this will work. as i can not test this as we do not have a spare ASA in our workshop.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;please find the below config.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;logging enable&lt;BR /&gt;logging timestamp&lt;BR /&gt;logging list SLA-LIST message 622001&lt;BR /&gt;logging buffer-size 9055&lt;BR /&gt;logging buffered debugging&lt;BR /&gt;logging trap SLA-LIST&lt;BR /&gt;logging history SLA-LIST&lt;BR /&gt;logging asdm debugging&lt;BR /&gt;logging mail SLA-LIST&lt;BR /&gt;logging from-address asa@netrevuca.co.uk&lt;BR /&gt;logging recipient-address sherazrose@netrevuca.co.uk level debugging&lt;BR /&gt;logging recipient-address itservicesdesk@netrevuca.co.uk level critical&lt;BR /&gt;logging device-id ipaddress inside&lt;BR /&gt;logging host inside 10.178.5.117&lt;BR /&gt;no logging message 106015&lt;BR /&gt;no logging message 313001&lt;BR /&gt;no logging message 313008&lt;BR /&gt;no logging message 106023&lt;BR /&gt;no logging message 710003&lt;BR /&gt;no logging message 106100&lt;BR /&gt;no logging message 302015&lt;BR /&gt;no logging message 302014&lt;BR /&gt;no logging message 302013&lt;BR /&gt;no logging message 302018&lt;BR /&gt;no logging message 302017&lt;BR /&gt;no logging message 302016&lt;BR /&gt;no logging message 302021&lt;BR /&gt;no logging message 302020&lt;BR /&gt;&lt;BR /&gt;snmp-server host inside 10.178.5.49 community ***** version 2c udp-port 161&lt;BR /&gt;snmp-server host inside 10.178.5.117 community ***** version 2c&lt;BR /&gt;snmp-server location GH&lt;BR /&gt;snmp-server contact IT&lt;BR /&gt;snmp-server community *****&lt;BR /&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart warmstart&lt;BR /&gt;snmp-server enable traps syslog&lt;BR /&gt;snmp-server enable traps ipsec start stop&lt;BR /&gt;snmp-server enable traps entity config-change fru-insert fru-remove&lt;BR /&gt;snmp-server enable traps memory-threshold&lt;BR /&gt;snmp-server enable traps interface-threshold&lt;BR /&gt;snmp-server enable traps remote-access session-threshold-exceeded&lt;BR /&gt;snmp-server enable traps connection-limit-reached&lt;BR /&gt;snmp-server enable traps cpu threshold rising&lt;BR /&gt;sysopt connection tcpmss 1350&lt;BR /&gt;sla monitor 1&lt;BR /&gt;&amp;nbsp;type echo protocol ipIcmpEcho 8.8.8.8 interface outside&lt;BR /&gt;&amp;nbsp;num-packets 2&lt;BR /&gt;&amp;nbsp;timeout 2000&lt;BR /&gt;&amp;nbsp;threshold 2000&lt;BR /&gt;&amp;nbsp;frequency 5&lt;BR /&gt;sla monitor schedule 1 life forever start-time now&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;class-map global-class&lt;BR /&gt;&amp;nbsp;description NetFlow_LCT_Export&lt;BR /&gt;&amp;nbsp;match any&lt;BR /&gt;class-map inspection_default&lt;BR /&gt;&amp;nbsp;match default-inspection-traffic&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;policy-map type inspect dns preset_dns_map&lt;BR /&gt;&amp;nbsp;parameters&lt;BR /&gt;&amp;nbsp; message-length maximum client auto&lt;BR /&gt;&amp;nbsp; message-length maximum 512&lt;BR /&gt;policy-map global_policy&lt;BR /&gt;&amp;nbsp;description NetFlow_LCT_Export&lt;BR /&gt;&amp;nbsp;class inspection_default&lt;BR /&gt;&amp;nbsp; inspect dns preset_dns_map&lt;BR /&gt;&amp;nbsp; inspect ftp&lt;BR /&gt;&amp;nbsp; inspect h323 h225&lt;BR /&gt;&amp;nbsp; inspect h323 ras&lt;BR /&gt;&amp;nbsp; inspect rsh&lt;BR /&gt;&amp;nbsp; inspect esmtp&lt;BR /&gt;&amp;nbsp; inspect sqlnet&lt;BR /&gt;&amp;nbsp; inspect skinny&lt;BR /&gt;&amp;nbsp; inspect sunrpc&lt;BR /&gt;&amp;nbsp; inspect xdmcp&lt;BR /&gt;&amp;nbsp; inspect sip&lt;BR /&gt;&amp;nbsp; inspect netbios&lt;BR /&gt;&amp;nbsp; inspect tftp&lt;BR /&gt;&amp;nbsp; inspect ip-options&lt;BR /&gt;&amp;nbsp;class global-class&lt;BR /&gt;&amp;nbsp; flow-export event-type all destination 10.178.5.117&lt;BR /&gt;&amp;nbsp;class class-default&lt;BR /&gt;&amp;nbsp; user-statistics accounting&lt;BR /&gt;!&lt;BR /&gt;service-policy global_policy global&lt;BR /&gt;smtp-server 10.178.1.113&lt;BR /&gt;prompt hostname context&lt;BR /&gt;no call-home reporting anonymous&lt;BR /&gt;hpm topN enable&lt;BR /&gt;Cryptochecksum:029395f06d6cc864531760c0e5210db9&lt;BR /&gt;: end&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 06:53:34 GMT</pubDate>
    <dc:creator>Sheraz.Salim</dc:creator>
    <dc:date>2019-03-12T06:53:34Z</dc:date>
    <item>
      <title>Firewall Email Alert config</title>
      <link>https://community.cisco.com/t5/network-security/firewall-email-alert-config/m-p/2835575#M165957</link>
      <description>&lt;P&gt;We have one outside interface connection to ISP. The ISP wanted to do some maintaince work and informed us the link will do down for half and hour. therefore I configured the email alert on our production network where is configured the IPSLA with syslog, SMTP and with email address could verify this will work. as i can not test this as we do not have a spare ASA in our workshop.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;please find the below config.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;logging enable&lt;BR /&gt;logging timestamp&lt;BR /&gt;logging list SLA-LIST message 622001&lt;BR /&gt;logging buffer-size 9055&lt;BR /&gt;logging buffered debugging&lt;BR /&gt;logging trap SLA-LIST&lt;BR /&gt;logging history SLA-LIST&lt;BR /&gt;logging asdm debugging&lt;BR /&gt;logging mail SLA-LIST&lt;BR /&gt;logging from-address asa@netrevuca.co.uk&lt;BR /&gt;logging recipient-address sherazrose@netrevuca.co.uk level debugging&lt;BR /&gt;logging recipient-address itservicesdesk@netrevuca.co.uk level critical&lt;BR /&gt;logging device-id ipaddress inside&lt;BR /&gt;logging host inside 10.178.5.117&lt;BR /&gt;no logging message 106015&lt;BR /&gt;no logging message 313001&lt;BR /&gt;no logging message 313008&lt;BR /&gt;no logging message 106023&lt;BR /&gt;no logging message 710003&lt;BR /&gt;no logging message 106100&lt;BR /&gt;no logging message 302015&lt;BR /&gt;no logging message 302014&lt;BR /&gt;no logging message 302013&lt;BR /&gt;no logging message 302018&lt;BR /&gt;no logging message 302017&lt;BR /&gt;no logging message 302016&lt;BR /&gt;no logging message 302021&lt;BR /&gt;no logging message 302020&lt;BR /&gt;&lt;BR /&gt;snmp-server host inside 10.178.5.49 community ***** version 2c udp-port 161&lt;BR /&gt;snmp-server host inside 10.178.5.117 community ***** version 2c&lt;BR /&gt;snmp-server location GH&lt;BR /&gt;snmp-server contact IT&lt;BR /&gt;snmp-server community *****&lt;BR /&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart warmstart&lt;BR /&gt;snmp-server enable traps syslog&lt;BR /&gt;snmp-server enable traps ipsec start stop&lt;BR /&gt;snmp-server enable traps entity config-change fru-insert fru-remove&lt;BR /&gt;snmp-server enable traps memory-threshold&lt;BR /&gt;snmp-server enable traps interface-threshold&lt;BR /&gt;snmp-server enable traps remote-access session-threshold-exceeded&lt;BR /&gt;snmp-server enable traps connection-limit-reached&lt;BR /&gt;snmp-server enable traps cpu threshold rising&lt;BR /&gt;sysopt connection tcpmss 1350&lt;BR /&gt;sla monitor 1&lt;BR /&gt;&amp;nbsp;type echo protocol ipIcmpEcho 8.8.8.8 interface outside&lt;BR /&gt;&amp;nbsp;num-packets 2&lt;BR /&gt;&amp;nbsp;timeout 2000&lt;BR /&gt;&amp;nbsp;threshold 2000&lt;BR /&gt;&amp;nbsp;frequency 5&lt;BR /&gt;sla monitor schedule 1 life forever start-time now&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;class-map global-class&lt;BR /&gt;&amp;nbsp;description NetFlow_LCT_Export&lt;BR /&gt;&amp;nbsp;match any&lt;BR /&gt;class-map inspection_default&lt;BR /&gt;&amp;nbsp;match default-inspection-traffic&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;policy-map type inspect dns preset_dns_map&lt;BR /&gt;&amp;nbsp;parameters&lt;BR /&gt;&amp;nbsp; message-length maximum client auto&lt;BR /&gt;&amp;nbsp; message-length maximum 512&lt;BR /&gt;policy-map global_policy&lt;BR /&gt;&amp;nbsp;description NetFlow_LCT_Export&lt;BR /&gt;&amp;nbsp;class inspection_default&lt;BR /&gt;&amp;nbsp; inspect dns preset_dns_map&lt;BR /&gt;&amp;nbsp; inspect ftp&lt;BR /&gt;&amp;nbsp; inspect h323 h225&lt;BR /&gt;&amp;nbsp; inspect h323 ras&lt;BR /&gt;&amp;nbsp; inspect rsh&lt;BR /&gt;&amp;nbsp; inspect esmtp&lt;BR /&gt;&amp;nbsp; inspect sqlnet&lt;BR /&gt;&amp;nbsp; inspect skinny&lt;BR /&gt;&amp;nbsp; inspect sunrpc&lt;BR /&gt;&amp;nbsp; inspect xdmcp&lt;BR /&gt;&amp;nbsp; inspect sip&lt;BR /&gt;&amp;nbsp; inspect netbios&lt;BR /&gt;&amp;nbsp; inspect tftp&lt;BR /&gt;&amp;nbsp; inspect ip-options&lt;BR /&gt;&amp;nbsp;class global-class&lt;BR /&gt;&amp;nbsp; flow-export event-type all destination 10.178.5.117&lt;BR /&gt;&amp;nbsp;class class-default&lt;BR /&gt;&amp;nbsp; user-statistics accounting&lt;BR /&gt;!&lt;BR /&gt;service-policy global_policy global&lt;BR /&gt;smtp-server 10.178.1.113&lt;BR /&gt;prompt hostname context&lt;BR /&gt;no call-home reporting anonymous&lt;BR /&gt;hpm topN enable&lt;BR /&gt;Cryptochecksum:029395f06d6cc864531760c0e5210db9&lt;BR /&gt;: end&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 06:53:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-email-alert-config/m-p/2835575#M165957</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2019-03-12T06:53:34Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/firewall-email-alert-config/m-p/2835576#M165958</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;From configuration if looks fine. It should work. Make sure reachability to SMTP server is there.&lt;/P&gt;
&lt;P&gt;&lt;B&gt;Note &lt;/B&gt;&lt;IMG src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" alt="" width="1" height="2" border="0" /&gt;&lt;SPAN&gt;We do not recommend using a severity level greater than 3 with the &lt;/SPAN&gt;&lt;B class="cCN_CmdName"&gt;logging recipient-address&lt;/B&gt;&lt;SPAN&gt; command. Higher severity levels are likely to cause dropped syslog messages because of buffer overflow.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/asa82/command/reference/cmd_ref/l2.html#wp1774041&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Also from the configuration, i could see that :&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;logging mail SLA-LIST&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;logging from-address asa@netrevuca.co.uk&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;logging recipient-address sherazrose@netrevuca.co.uk level debugging&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;logging recipient-address itservicesdesk@netrevuca.co.uk level critical&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;You have configured Logging list with specific message and simultaneously you have configured severity level in receipient-address. Recipient address's level always overrdes the one configured in logging mail. Therefore first recipient would get messages till debugging, and 2nd with critical. However as mentioned earlier, debugging level is too high. So you could thing of changing it to low level.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Hope it helps.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Akshay Rastogi&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Nov 2015 16:08:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-email-alert-config/m-p/2835576#M165958</guid>
      <dc:creator>Akshay Rastogi</dc:creator>
      <dc:date>2015-11-16T16:08:57Z</dc:date>
    </item>
  </channel>
</rss>

