<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi, Glad to hear all is in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asdm-traffic-logs/m-p/2582890#M199224</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Glad to hear all is working now. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please do remember to rate any helpfull answers or mark a reply as the correct answer if it answered your question.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;</description>
    <pubDate>Tue, 20 Jan 2015 13:52:41 GMT</pubDate>
    <dc:creator>Jouni Forss</dc:creator>
    <dc:date>2015-01-20T13:52:41Z</dc:date>
    <item>
      <title>ASDM Traffic Logs</title>
      <link>https://community.cisco.com/t5/network-security/asdm-traffic-logs/m-p/2582881#M199200</link>
      <description>&lt;P&gt;I'm fairly new to ASDM so I apologize for this noob question. I need to see what is actually passing through a specific source IP and destination IP, my goal is to identify which specific ports I'm missing on an IP ruleset. My logging is setup to "Debugging" but I can't seem to see what ports are being dropped/allowed whenever I check the Log Buffer &amp;amp; Real-Time Log Viewer.Do I need to setup some sort of packet trace? Need help on setting up filters please.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 05:19:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asdm-traffic-logs/m-p/2582881#M199200</guid>
      <dc:creator>Yves Alob</dc:creator>
      <dc:date>2019-03-12T05:19:44Z</dc:date>
    </item>
    <item>
      <title>Hi, I don't deal with ASDM</title>
      <link>https://community.cisco.com/t5/network-security/asdm-traffic-logs/m-p/2582882#M199202</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't deal with ASDM that much but I do use it mainly for the same thing as you are trying to use it for which is to monitor live some connections/connection attempts.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am not sure what the problem in this situation is. Can you confirm that you can atleast some logs on the ASDM when no filter is applied? Can you see any logs on the &lt;STRONG&gt;"Home"&lt;/STRONG&gt; pages &lt;STRONG&gt;"Device Dashboard"&lt;/STRONG&gt; ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When you are looking at the logs through the actual &lt;STRONG&gt;"Monitoring"&lt;/STRONG&gt; section and open the separate logging window you should see a button called &lt;STRONG&gt;"Build Filter"&lt;/STRONG&gt; which provides you with different parameters with which you can filter the logs shown in the window.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If the traffic is blocked by the interface ACL you can probably even search for the logs with the Sylog ID 106023&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can naturally start by using destination/source IP address and see if you can get anything to show up. It might even be possible that the traffic is not even reaching this firewall?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jan 2015 08:27:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asdm-traffic-logs/m-p/2582882#M199202</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2015-01-12T08:27:09Z</dc:date>
    </item>
    <item>
      <title>Alright,here is the scenario.</title>
      <link>https://community.cisco.com/t5/network-security/asdm-traffic-logs/m-p/2582883#M199204</link>
      <description>&lt;P&gt;Alright,here is the scenario. I have a request coming from a user to grant access to a cctv system. I created an ip ruleset for this but unfortunately, the access is still not working. What I'm trying to look up, is what specific ports am I missing which causes the problem. I have allowed 'IP' on the ruleset, and traffic went through which means I'm missing some specific ports. I can see logs on the dashboard &amp;amp; monitoring section, but I can't seem to see what ports are being dropped and from what source &amp;amp; to what destination.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jan 2015 09:36:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asdm-traffic-logs/m-p/2582883#M199204</guid>
      <dc:creator>Yves Alob</dc:creator>
      <dc:date>2015-01-12T09:36:09Z</dc:date>
    </item>
    <item>
      <title>Hi, If you are seeing the</title>
      <link>https://community.cisco.com/t5/network-security/asdm-traffic-logs/m-p/2582884#M199206</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you are seeing the logs in the monitoring windows then you should be looking for log messages that (by default) are colored yellow. They should also mention at the end the name of the ACL that blocks the traffic. The log message in itself should show the source/destination IP addresses and ports of this blocked connection attempt.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You should be able to build a Filter using the IP addresses alone to catch that traffic. Perhaps use the source IP address first and narrow it down if needed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jan 2015 11:49:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asdm-traffic-logs/m-p/2582884#M199206</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2015-01-12T11:49:49Z</dc:date>
    </item>
    <item>
      <title>Hello Jouni,I can only see</title>
      <link>https://community.cisco.com/t5/network-security/asdm-traffic-logs/m-p/2582885#M199211</link>
      <description>&lt;P&gt;Hello Jouni,&lt;/P&gt;&lt;P&gt;I can only see severity 6 &amp;amp; 7 logs although my logging filters are set to 'debugging'. Please see attached screenshots. I do not see the colored yellow logs, I'm sure I'm just missing something on the setup.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yves&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jan 2015 07:03:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asdm-traffic-logs/m-p/2582885#M199211</guid>
      <dc:creator>Yves Alob</dc:creator>
      <dc:date>2015-01-13T07:03:38Z</dc:date>
    </item>
    <item>
      <title>Hi, You could go to the CLI</title>
      <link>https://community.cisco.com/t5/network-security/asdm-traffic-logs/m-p/2582886#M199216</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You could go to the CLI (command line) or use the CLI tool on the ASDM (top menu) to insert the command&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show run logging&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With this we should see if you have disabled any log message IDs from showing. You are seeing debugging messages so you should also be seeing the deny messsages which to my understanding are Notifications level messages (5)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jan 2015 07:24:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asdm-traffic-logs/m-p/2582886#M199216</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2015-01-13T07:24:13Z</dc:date>
    </item>
    <item>
      <title>Hi,Please see show results</title>
      <link>https://community.cisco.com/t5/network-security/asdm-traffic-logs/m-p/2582887#M199219</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Please see show results below:&lt;/P&gt;&lt;P&gt;Firewall# show run logging&lt;BR /&gt;logging enable&lt;BR /&gt;logging timestamp&lt;BR /&gt;logging standby&lt;BR /&gt;logging monitor debugging&lt;BR /&gt;logging buffered notifications&lt;BR /&gt;logging trap debugging&lt;BR /&gt;logging asdm debugging&lt;BR /&gt;logging host Management 10.X.X.X&lt;BR /&gt;logging host Management 10.X.X.X&lt;BR /&gt;no logging message 106015&lt;BR /&gt;no logging message 313001&lt;BR /&gt;no logging message 313008&lt;BR /&gt;no logging message 106023&lt;BR /&gt;no logging message 710003&lt;BR /&gt;no logging message 106100&lt;BR /&gt;no logging message 302015&lt;BR /&gt;no logging message 302014&lt;BR /&gt;no logging message 302013&lt;BR /&gt;no logging message 302018&lt;BR /&gt;no logging message 302017&lt;BR /&gt;no logging message 302016&lt;BR /&gt;no logging message 302021&lt;BR /&gt;no logging message 302020&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jan 2015 08:11:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asdm-traffic-logs/m-p/2582887#M199219</guid>
      <dc:creator>Yves Alob</dc:creator>
      <dc:date>2015-01-13T08:11:34Z</dc:date>
    </item>
    <item>
      <title>Hi, If you check my earlier</title>
      <link>https://community.cisco.com/t5/network-security/asdm-traffic-logs/m-p/2582888#M199221</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you check my earlier messages you will see that I mentioned the Syslog ID 106023. In your above list its disabled so that is why the ASDM is not showing the logs. And if I can remember correctly you also have disabled some logs that show when a connection is built and torn down from the ASA. The mentioned log messages in my opinion are pretty important messages to record to Syslog server. They are great to have when a user reports a problem that might have begun several days ago or you are possibly trying to track and find a computer in your network that is causing spam and possibly blacklisting your public IPs and so on.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So you would have to enter this command&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;logging message 106023&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also all these disabled IDs are log messages that record TCP/UDP/ICMP connection forming and teardown&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;no logging message 302015&lt;BR /&gt;no logging message 302014&lt;BR /&gt;no logging message 302013&lt;BR /&gt;no logging message 302018&lt;BR /&gt;no logging message 302017&lt;BR /&gt;no logging message 302016&lt;BR /&gt;no logging message 302021&lt;BR /&gt;no logging message 302020&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Basically it means you are not recording any connections that are formed through your firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also this Syslog ID is related to a situation when ASA blocks some traffic&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;no logging message 106100&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jan 2015 08:19:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asdm-traffic-logs/m-p/2582888#M199221</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2015-01-13T08:19:10Z</dc:date>
    </item>
    <item>
      <title>Jouni, Thanks for your help!</title>
      <link>https://community.cisco.com/t5/network-security/asdm-traffic-logs/m-p/2582889#M199222</link>
      <description>&lt;P&gt;Jouni,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your help!&amp;nbsp;I am now able to see notification logs &amp;amp; build a filter. Appreciate your inputs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Yves&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jan 2015 08:33:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asdm-traffic-logs/m-p/2582889#M199222</guid>
      <dc:creator>Yves Alob</dc:creator>
      <dc:date>2015-01-20T08:33:41Z</dc:date>
    </item>
    <item>
      <title>Hi, Glad to hear all is</title>
      <link>https://community.cisco.com/t5/network-security/asdm-traffic-logs/m-p/2582890#M199224</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Glad to hear all is working now. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please do remember to rate any helpfull answers or mark a reply as the correct answer if it answered your question.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jan 2015 13:52:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asdm-traffic-logs/m-p/2582890#M199224</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2015-01-20T13:52:41Z</dc:date>
    </item>
    <item>
      <title>Re: Hi, I don't deal with ASDM</title>
      <link>https://community.cisco.com/t5/network-security/asdm-traffic-logs/m-p/3877348#M199225</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Your reply guided me where to look but the interface is slightly different in ASDM Version 7.6(1) ASA Verson 9.6(2)3&lt;/P&gt;&lt;P&gt;And the Real Time log viewer is located under&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Monitoring -&amp;gt;Logging -&amp;gt;Real-Time Log Viewer&lt;/STRONG&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I set the logging level to Informational because debugging could be overwhelming.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jun 2019 11:30:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asdm-traffic-logs/m-p/3877348#M199225</guid>
      <dc:creator>Zaaf Aba</dc:creator>
      <dc:date>2019-06-21T11:30:39Z</dc:date>
    </item>
  </channel>
</rss>

