<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Firewall access rule log hits in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firewall-access-rule-log-hits/m-p/2476828#M267554</link>
    <description>&lt;P&gt;I set up an access rule to deny any any out port 25.&amp;nbsp; I have some hits and want to know what ip address is hitting the access rule.&amp;nbsp; How do I set up logging?&amp;nbsp; Then how do I view the log to see the hits?&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 04:04:30 GMT</pubDate>
    <dc:creator>jbaldwin33</dc:creator>
    <dc:date>2019-03-12T04:04:30Z</dc:date>
    <item>
      <title>Firewall access rule log hits</title>
      <link>https://community.cisco.com/t5/network-security/firewall-access-rule-log-hits/m-p/2476828#M267554</link>
      <description>&lt;P&gt;I set up an access rule to deny any any out port 25.&amp;nbsp; I have some hits and want to know what ip address is hitting the access rule.&amp;nbsp; How do I set up logging?&amp;nbsp; Then how do I view the log to see the hits?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 04:04:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-access-rule-log-hits/m-p/2476828#M267554</guid>
      <dc:creator>jbaldwin33</dc:creator>
      <dc:date>2019-03-12T04:04:30Z</dc:date>
    </item>
    <item>
      <title>Hi, What FW is it?You can see</title>
      <link>https://community.cisco.com/t5/network-security/firewall-access-rule-log-hits/m-p/2476829#M267557</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;What FW is it?&lt;/P&gt;&lt;P&gt;You can see logs in ASDM (GUI interface). Access the ASA through the GUI interface (ASDM).&lt;/P&gt;&lt;P&gt;Once you log in to the ASDM, go to&lt;/P&gt;&lt;P&gt;Configuration &amp;gt; firwall &amp;gt; access rules&lt;/P&gt;&lt;P&gt;Right Click on the rule that you had created and choose show log.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You will be able to see the ip addresses hitting it. The real time application of the rule.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For logging.&lt;/P&gt;&lt;P&gt;Install a syslog server and configure the FWs syslog server settings to point to that server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps. Let me know if you need more help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Apr 2014 19:04:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-access-rule-log-hits/m-p/2476829#M267557</guid>
      <dc:creator>Mujtaba Imran Mohammed</dc:creator>
      <dc:date>2014-04-14T19:04:14Z</dc:date>
    </item>
  </channel>
</rss>

