<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Thank you for your response! in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firewall-rule-debugging/m-p/2561557#M202571</link>
    <description>&lt;P&gt;Thank you for your response!&lt;/P&gt;</description>
    <pubDate>Wed, 10 Dec 2014 19:26:52 GMT</pubDate>
    <dc:creator>web_hosting</dc:creator>
    <dc:date>2014-12-10T19:26:52Z</dc:date>
    <item>
      <title>Firewall Rule Debugging</title>
      <link>https://community.cisco.com/t5/network-security/firewall-rule-debugging/m-p/2561555#M202569</link>
      <description>&lt;P&gt;Hello.&amp;nbsp; I am new to Cisco firewall rules and I was hoping you could help me. I have done some research, but I am not 100% on a few things.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Background: I have a few broad rules that are getting hit counts, but I am not expecting the hits, so I am trying to determine the traffic.&amp;nbsp; In an ideal world, I would be able to turn on debugging/logging of just the specific rules in question to determine the traffic.&amp;nbsp; I have some questions that revolve around this solution.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Questions:&lt;/P&gt;&lt;P&gt;1) I need to know source and destination IP and port.&amp;nbsp; Is that a logging level of 4 or 6 that will achieve that?&lt;/P&gt;&lt;P&gt;2) All of our rules have "log" appended to the end. Does that mean that the global logging level you set, applies to all rules with "log" appended?&lt;/P&gt;&lt;P&gt;3) I did not fully understand the content in regards to creating classes or message lists. Is there a way to set a different logging rule for a specific rule?&lt;/P&gt;&lt;P&gt;4) If you one cannot apply to a specific rule, is one possible solution, putting the rule in its own ACL and putting this ACL above the rest?&amp;nbsp; If I understand correctly, you can add unique debugging/logging to a specific ACL?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Dallas&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 05:12:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-rule-debugging/m-p/2561555#M202569</guid>
      <dc:creator>web_hosting</dc:creator>
      <dc:date>2019-03-12T05:12:10Z</dc:date>
    </item>
    <item>
      <title>1) I need to know source and</title>
      <link>https://community.cisco.com/t5/network-security/firewall-rule-debugging/m-p/2561556#M202570</link>
      <description>&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;1) I need to know source and destination IP and port.&amp;nbsp; Is that a logging level of 4 or 6 that will achieve that?&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;Logging level 6 is what you want.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;2) All of our rules have "log" appended to the end. Does that mean that the global logging level you set, applies to all rules with "log" appended?&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Correct, when you set the logging level, this level applies to everything you are logging.&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;3) I did not fully understand the content in regards to creating classes or message lists. Is there a way to set a different logging rule for a specific rule?&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;Basically, the ACL class and message-lists are used for logging specified syslog messages in a different syslog level.&amp;nbsp; For example, you can use this to log informational level messages that you specify as critical messages.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;4) If you one cannot apply to a specific rule, is one possible solution, putting the rule in its own ACL and putting this ACL above the rest?&amp;nbsp; If I understand correctly, you can add unique debugging/logging to a specific ACL?&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;You can not "debug" an ACL, but you can create a packet capture between two interfaces which references an ACL.&amp;nbsp; Then you can export that capture file and analyze it in Wireshark.&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportforums.cisco.com/document/69281/asa-using-packet-capture-troubleshoot-asa-firewall-configuration-and-scenarios"&gt;https://supportforums.cisco.com/document/69281/asa-using-packet-capture-troubleshoot-asa-firewall-configuration-and-scenarios&lt;/A&gt;&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Please remember to select a correct answer and rate helpful posts&lt;/P&gt;</description>
      <pubDate>Wed, 10 Dec 2014 07:40:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-rule-debugging/m-p/2561556#M202570</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2014-12-10T07:40:14Z</dc:date>
    </item>
    <item>
      <title>Thank you for your response!</title>
      <link>https://community.cisco.com/t5/network-security/firewall-rule-debugging/m-p/2561557#M202571</link>
      <description>&lt;P&gt;Thank you for your response!&lt;/P&gt;</description>
      <pubDate>Wed, 10 Dec 2014 19:26:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-rule-debugging/m-p/2561557#M202571</guid>
      <dc:creator>web_hosting</dc:creator>
      <dc:date>2014-12-10T19:26:52Z</dc:date>
    </item>
  </channel>
</rss>

