<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Looks like i am reaching in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/disable-all-asa-logging-and-only-specific-acl-logging/m-p/2792379#M174379</link>
    <description>&lt;P&gt;Looks like i am reaching somewhere. disabled alot of other message level. and now i can see some 106001 messages. which were previously overwritten due to massive logs, i think have narrowed it down a bit. will update in a while.&lt;/P&gt;
&lt;P&gt;no logging message 106015&lt;BR /&gt;no logging message 313005&lt;BR /&gt;no logging message 106001&lt;BR /&gt;no logging message 106023&lt;BR /&gt;no logging message 305006&lt;BR /&gt;no logging message 305012&lt;BR /&gt;no logging message 305011&lt;BR /&gt;no logging message 302015&lt;BR /&gt;no logging message 302014&lt;BR /&gt;no logging message 302013&lt;BR /&gt;no logging message 302016&lt;BR /&gt;no logging message 302021&lt;BR /&gt;no logging message 302020&lt;/P&gt;</description>
    <pubDate>Thu, 03 Dec 2015 17:39:07 GMT</pubDate>
    <dc:creator>ahmad82pkn</dc:creator>
    <dc:date>2015-12-03T17:39:07Z</dc:date>
    <item>
      <title>Disable all ASA logging and Only Specific ACL Logging</title>
      <link>https://community.cisco.com/t5/network-security/disable-all-asa-logging-and-only-specific-acl-logging/m-p/2792374#M174370</link>
      <description>&lt;P&gt;Hi, we have a bit wide open Cisco ASA in term of ACL and we want to tighten it.&lt;/P&gt;
&lt;P&gt;but there are lots of LOGS generated by ASA and its hard to filter required information.&lt;/P&gt;
&lt;P&gt;What i need to achieve is Disable all logging for time being and only LOG a particular Permit ACL to see what is gettign allowed due to that default mis configured rule.&lt;/P&gt;
&lt;P&gt;For example i want no other logs in syslog except logs of below ACL to s ee what is getting permitted&lt;/P&gt;
&lt;P&gt;access-list MYACL permit ip 192.168.100.0 255.255.255.255 10.0.0.0 255.0.0.0&lt;/P&gt;
&lt;P&gt;how can i acheive this?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 06:58:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disable-all-asa-logging-and-only-specific-acl-logging/m-p/2792374#M174370</guid>
      <dc:creator>ahmad82pkn</dc:creator>
      <dc:date>2019-03-12T06:58:51Z</dc:date>
    </item>
    <item>
      <title>Hi Ahmed,</title>
      <link>https://community.cisco.com/t5/network-security/disable-all-asa-logging-and-only-specific-acl-logging/m-p/2792375#M174371</link>
      <description>&lt;P&gt;Hi Ahmad,&lt;/P&gt;
&lt;P&gt;You can disable the logging in the ACL configuration &amp;nbsp;with &amp;nbsp;"log disable" at the end of the ACL command&lt;/P&gt;
&lt;P&gt;For example:&amp;nbsp; access-list test extended permit ip a any log disable&lt;/P&gt;
&lt;P&gt;You can refer this link to modify the ACL parameters using the ASDM.&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/112925-acl-asdm-00.html&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;BR /&gt;Shivapramod M&lt;BR /&gt;Please remember to select a correct answer and rate helpful posts&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Dec 2015 01:41:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disable-all-asa-logging-and-only-specific-acl-logging/m-p/2792375#M174371</guid>
      <dc:creator>Shivapramod M</dc:creator>
      <dc:date>2015-12-03T01:41:39Z</dc:date>
    </item>
    <item>
      <title>Thank you for the reply Shiva</title>
      <link>https://community.cisco.com/t5/network-security/disable-all-asa-logging-and-only-specific-acl-logging/m-p/2792376#M174373</link>
      <description>&lt;P&gt;Thank you for the reply Shiva. is there anyother way ? as i have literally thousands of ACL lines, and i dont want to type disable in front of all ACL.&lt;/P&gt;
&lt;P&gt;i though some global command to disable all logging and only enable for particular ACL.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Dec 2015 08:16:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disable-all-asa-logging-and-only-specific-acl-logging/m-p/2792376#M174373</guid>
      <dc:creator>ahmad82pkn</dc:creator>
      <dc:date>2015-12-03T08:16:16Z</dc:date>
    </item>
    <item>
      <title>Hi Ahmad,</title>
      <link>https://community.cisco.com/t5/network-security/disable-all-asa-logging-and-only-specific-acl-logging/m-p/2792377#M174375</link>
      <description>&lt;P&gt;Hi Ahmad,&lt;/P&gt;
&lt;P&gt;Have you configured the access list with the "log" keyword?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Where are you pushing these logs to?&lt;/P&gt;
&lt;P&gt;By default if &lt;SPAN&gt;&amp;nbsp;you have &lt;/SPAN&gt;&lt;STRONG&gt;"permit"&lt;/STRONG&gt;&lt;SPAN&gt; rules then these wont generate any log by default. Normally the ASA generates logs about connections that are denied by an ACL. But if you have the "log" keyword in the ACL then it will generate the logs.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks,&lt;BR /&gt;&lt;SPAN&gt;Shivapramod M&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Dec 2015 12:28:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disable-all-asa-logging-and-only-specific-acl-logging/m-p/2792377#M174375</guid>
      <dc:creator>Shivapramod M</dc:creator>
      <dc:date>2015-12-03T12:28:19Z</dc:date>
    </item>
    <item>
      <title>i have disabled all Deny Logs</title>
      <link>https://community.cisco.com/t5/network-security/disable-all-asa-logging-and-only-specific-acl-logging/m-p/2792378#M174377</link>
      <description>&lt;P&gt;i have disabled all Deny/NAT and Logs by this to achieve only desired logs&lt;/P&gt;
&lt;P&gt;no logging message 106023&lt;BR /&gt;no logging message 305006&lt;BR /&gt;no logging message 305012&lt;BR /&gt;no logging message 305011&lt;BR /&gt;no logging message 302015&lt;BR /&gt;no logging message 302014&lt;BR /&gt;no logging message 302016&lt;BR /&gt;no logging message 302021&lt;BR /&gt;no logging message 302020&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;i have created LOG Key word on my Desired ACL.&lt;/P&gt;
&lt;P&gt;access-list DMZ line 297 extended permit ip 192.168.220.0 255.255.255.0 10.24.21.0 255.255.255.0 log debugging interval 300 (hitcnt=795)&lt;/P&gt;
&lt;P&gt;but i am getting lots of other Permit Logs as well, causing difficult to filter desired logs.&lt;/P&gt;
&lt;P&gt;whereas no other ACL has log keyword in them. Not sure how to block those permit Logs for example Below is coming in Syslog as well&lt;/P&gt;
&lt;TABLE class="Report" cellpadding="0" cellspacing="0" width="100%"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD class="Severity6"&gt;&lt;A tooltip="processed" href="http://10.80.10.68:8060/Orion/NetPerfMon/NodeDetails.aspx?NetObject=N:166"&gt;764870321&lt;/A&gt;&lt;/TD&gt;
&lt;TD class="Severity6"&gt;Informational&lt;/TD&gt;
&lt;TD class="Severity6"&gt;%PIX-6-302013: Built outbound TCP connection 816704746 for TRG-DMZ:192.168.220.154/80 (192.168.220.154/80) to INSIDE:10.6.5.30/53190 (192.168.220.200/3498)&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;whereas it shouldnt come.&lt;/P&gt;
&lt;P&gt;i also configured this line&lt;/P&gt;
&lt;P&gt;logging trap informational&lt;/P&gt;</description>
      <pubDate>Thu, 03 Dec 2015 16:48:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disable-all-asa-logging-and-only-specific-acl-logging/m-p/2792378#M174377</guid>
      <dc:creator>ahmad82pkn</dc:creator>
      <dc:date>2015-12-03T16:48:34Z</dc:date>
    </item>
    <item>
      <title>Looks like i am reaching</title>
      <link>https://community.cisco.com/t5/network-security/disable-all-asa-logging-and-only-specific-acl-logging/m-p/2792379#M174379</link>
      <description>&lt;P&gt;Looks like i am reaching somewhere. disabled alot of other message level. and now i can see some 106001 messages. which were previously overwritten due to massive logs, i think have narrowed it down a bit. will update in a while.&lt;/P&gt;
&lt;P&gt;no logging message 106015&lt;BR /&gt;no logging message 313005&lt;BR /&gt;no logging message 106001&lt;BR /&gt;no logging message 106023&lt;BR /&gt;no logging message 305006&lt;BR /&gt;no logging message 305012&lt;BR /&gt;no logging message 305011&lt;BR /&gt;no logging message 302015&lt;BR /&gt;no logging message 302014&lt;BR /&gt;no logging message 302013&lt;BR /&gt;no logging message 302016&lt;BR /&gt;no logging message 302021&lt;BR /&gt;no logging message 302020&lt;/P&gt;</description>
      <pubDate>Thu, 03 Dec 2015 17:39:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disable-all-asa-logging-and-only-specific-acl-logging/m-p/2792379#M174379</guid>
      <dc:creator>ahmad82pkn</dc:creator>
      <dc:date>2015-12-03T17:39:07Z</dc:date>
    </item>
    <item>
      <title>Is there anyway to disable</title>
      <link>https://community.cisco.com/t5/network-security/disable-all-asa-logging-and-only-specific-acl-logging/m-p/2792380#M174381</link>
      <description>&lt;P&gt;Is there anyway to disable all informational meessages except one that is 106100 ?&lt;/P&gt;</description>
      <pubDate>Thu, 03 Dec 2015 17:46:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disable-all-asa-logging-and-only-specific-acl-logging/m-p/2792380#M174381</guid>
      <dc:creator>ahmad82pkn</dc:creator>
      <dc:date>2015-12-03T17:46:12Z</dc:date>
    </item>
  </channel>
</rss>

