<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA 5520 - Security Audit in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5520-security-audit/m-p/2357212#M308915</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Thanks guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I actually did setup a syslog server thinking that was going to be the ticket but wasn't 100% sure.&amp;nbsp; I will take a look at Netflow options down the road.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 18 Nov 2013 16:06:42 GMT</pubDate>
    <dc:creator>gregorysieg</dc:creator>
    <dc:date>2013-11-18T16:06:42Z</dc:date>
    <item>
      <title>ASA 5520 - Security Audit</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-security-audit/m-p/2357209#M308910</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to pull a report for the last 24 hours of all external connection attempts to our ASA.&amp;nbsp; I went into Monitoring via the ASMD (7.1) and changed the logging level to "Informational" however I do not see anything coming in it only seems to be showing my internal going out.&amp;nbsp; Could someone please supply me with some information or direction on where I could find documents for this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Greg&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 03:05:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-security-audit/m-p/2357209#M308910</guid>
      <dc:creator>gregorysieg</dc:creator>
      <dc:date>2019-03-12T03:05:05Z</dc:date>
    </item>
    <item>
      <title>ASA 5520 - Security Audit</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-security-audit/m-p/2357210#M308911</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The ASA has a logging buffer that by default is short, it is expected that if you are monitoring traffic to or through the ASA you configure a Syslog server since past events are not saved into disk unless specified.&lt;SPAN __jive_emoticon_name="cry" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/tiny_mce3/plugins/jiveemoticons/images/spacer.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Nov 2013 21:18:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-security-audit/m-p/2357210#M308911</guid>
      <dc:creator>jumora</dc:creator>
      <dc:date>2013-11-14T21:18:15Z</dc:date>
    </item>
    <item>
      <title>ASA 5520 - Security Audit</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-security-audit/m-p/2357211#M308913</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Gregory&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My recommendation for this is to leverage the UDP Syslog packets to a External device so you can save memory on the ASA for different traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note: You should consider Netflow as it will provide you granularity and also depending on the vendor software they will build reports, etc on their own with the data send to the collector.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rate all of the helpful posts!!! &lt;BR /&gt; &lt;BR /&gt;Regards, &lt;BR /&gt; &lt;BR /&gt;Jcarvaja &lt;BR /&gt; &lt;BR /&gt;&lt;SPAN&gt;Follow me on &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://laguiadelnetworking.com"&gt;http://laguiadelnetworking.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Nov 2013 22:26:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-security-audit/m-p/2357211#M308913</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-11-14T22:26:35Z</dc:date>
    </item>
    <item>
      <title>ASA 5520 - Security Audit</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-security-audit/m-p/2357212#M308915</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Thanks guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I actually did setup a syslog server thinking that was going to be the ticket but wasn't 100% sure.&amp;nbsp; I will take a look at Netflow options down the road.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Nov 2013 16:06:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-security-audit/m-p/2357212#M308915</guid>
      <dc:creator>gregorysieg</dc:creator>
      <dc:date>2013-11-18T16:06:42Z</dc:date>
    </item>
    <item>
      <title>ASA 5520 - Security Audit</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-security-audit/m-p/2357213#M308918</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Guys,&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a Syslog up and running but am finding I'm not really getting the information I was expecting.&amp;nbsp;&amp;nbsp; I was thinking I would see numerous denied attempts to say port 3389, 23, or other well known ports but really I'm pretty much just seeing alot of "Teardown connections", "Built connections", "Access List permitted", and some randle "Deny TCP (no connection).&amp;nbsp; Now I think the Deny TCP (no connection) may be what I'm looking for but I really expected to see quite a bit more of this type of traffic?&amp;nbsp; I figured I'd pick up some port scanning attempts or something maybe it's there and I just am not viewing it correctly or maybe I'm looking in the wrong place?&amp;nbsp; Maybe I'm just expecting more negative then I should be.&amp;nbsp; Any thoughts?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Greg&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Nov 2013 17:47:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-security-audit/m-p/2357213#M308918</guid>
      <dc:creator>gregorysieg</dc:creator>
      <dc:date>2013-11-22T17:47:23Z</dc:date>
    </item>
    <item>
      <title>ASA 5520 - Security Audit</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-security-audit/m-p/2357214#M308919</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Greg,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So you are not seeing any Deny ACL???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Look for log ID 106023&lt;/P&gt;&lt;P id="stcpDiv" style="position: absolute; top: -1999px; left: -1988px;"&gt;106023&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P id="stcpDiv" style="position: absolute; top: -1999px; left: -1988px;"&gt;106023&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P id="stcpDiv" style="position: absolute; top: -1999px; left: -1988px;"&gt;106023&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P id="stcpDiv" style="position: absolute; top: -1999px; left: -1988px;"&gt;106023&lt;/P&gt;&lt;P id="stcpDiv" style="position: absolute; top: -1999px; left: -1988px;"&gt;106023 p&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P id="stcpDiv" style="position: absolute; top: -1999px; left: -1988px;"&gt;106023 p&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rate all of the helpful posts!!! &lt;BR /&gt; &lt;BR /&gt;Regards, &lt;BR /&gt; &lt;BR /&gt;Jcarvaja &lt;BR /&gt; &lt;BR /&gt;&lt;SPAN&gt;Follow me on &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://laguiadelnetworking.com"&gt;http://laguiadelnetworking.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Nov 2013 18:38:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-security-audit/m-p/2357214#M308919</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-11-22T18:38:01Z</dc:date>
    </item>
  </channel>
</rss>

