<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi Jim, thanks for your reply in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-asa-acl-logging-based-on-source-ip-not-working/m-p/2444882#M267732</link>
    <description>&lt;P&gt;Hi Jim, thanks for your reply.&lt;/P&gt;&lt;P&gt;Is there any command/utility like the "shun" command that can work on "live packets" which are been already permitted first by other ACL rule?&lt;/P&gt;&lt;P&gt;Re-ordering acl would be difficult because its a live circuit.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks again - Jami.&lt;/P&gt;</description>
    <pubDate>Thu, 10 Apr 2014 00:33:25 GMT</pubDate>
    <dc:creator>mjami</dc:creator>
    <dc:date>2014-04-10T00:33:25Z</dc:date>
    <item>
      <title>Cisco ASA acl logging based on source IP not working</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-acl-logging-based-on-source-ip-not-working/m-p/2444880#M267730</link>
      <description>&lt;P&gt;I have got two Cisco ASA 5520 running with IOS version 8.4.&lt;/P&gt;&lt;P&gt;I am trying to get all the packet events for a given "specific source" IP address &amp;gt; send to a syslog server. Syslog server has been configured and working fine for other ASA events.&lt;/P&gt;&lt;P&gt;I have created new ACL rule to log all events for that specific source IP address to syslog server - but noting showing on syslog logs because (??) of packets already permitted by other ACL rule sitting on the top.&lt;/P&gt;&lt;P&gt;I use the following ACL rule -&lt;/P&gt;&lt;P&gt;#access-list aclName extended permit ip host x.x.x.x any log debugging&lt;/P&gt;&lt;P&gt;ACL hitcount is zero but I am getting that "specific source IP" at ASDM live traffic monitoring.&lt;/P&gt;&lt;P&gt;Could anyone please shed some light on this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 04:02:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-acl-logging-based-on-source-ip-not-working/m-p/2444880#M267730</guid>
      <dc:creator>mjami</dc:creator>
      <dc:date>2019-03-12T04:02:49Z</dc:date>
    </item>
    <item>
      <title>You might need to re-order</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-acl-logging-based-on-source-ip-not-working/m-p/2444881#M267731</link>
      <description>&lt;P&gt;You might need to re-order your access-list rules to put the "permit ... log" one much earlier.&amp;nbsp; Remember that ASA's do first match; the first permit or deny rule which matches a packet controls its fate, regardless of any subsequent rules.&lt;/P&gt;&lt;P&gt;-- Jim Leinweber, WI State Lab of Hygiene&lt;/P&gt;</description>
      <pubDate>Wed, 09 Apr 2014 15:39:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-acl-logging-based-on-source-ip-not-working/m-p/2444881#M267731</guid>
      <dc:creator>James Leinweber</dc:creator>
      <dc:date>2014-04-09T15:39:08Z</dc:date>
    </item>
    <item>
      <title>Hi Jim, thanks for your reply</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-acl-logging-based-on-source-ip-not-working/m-p/2444882#M267732</link>
      <description>&lt;P&gt;Hi Jim, thanks for your reply.&lt;/P&gt;&lt;P&gt;Is there any command/utility like the "shun" command that can work on "live packets" which are been already permitted first by other ACL rule?&lt;/P&gt;&lt;P&gt;Re-ordering acl would be difficult because its a live circuit.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks again - Jami.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Apr 2014 00:33:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-acl-logging-based-on-source-ip-not-working/m-p/2444882#M267732</guid>
      <dc:creator>mjami</dc:creator>
      <dc:date>2014-04-10T00:33:25Z</dc:date>
    </item>
    <item>
      <title>Reording the ACL will not</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-acl-logging-based-on-source-ip-not-working/m-p/2444883#M267733</link>
      <description>&lt;P&gt;Reording the ACL will not affect other traffic.&amp;nbsp; depending on if you use the ASDM or CLI:&amp;nbsp; In the ASDM select the rule you want to place higher and then use the arrow buttons toward the top left of the page to move it up, then click apply.&lt;/P&gt;&lt;P&gt;in CLI, remove the ACL entry and then re enter it but this time issue the sequence number where you want to place it.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list aclName line 5 extended permit ip host x.x.x.x any log debugging&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;the above ACL will "squeeze" the ACL in to position 5 in the ACL order.&amp;nbsp; All lower ACLs will be reordered automatically.&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Please remember to rate and select a correct answer&lt;/P&gt;</description>
      <pubDate>Thu, 10 Apr 2014 08:43:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-acl-logging-based-on-source-ip-not-working/m-p/2444883#M267733</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2014-04-10T08:43:46Z</dc:date>
    </item>
  </channel>
</rss>

