<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Help Syslog in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/help-syslog/m-p/2332576#M310403</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you have not denied either and by default is enabled. As long&amp;nbsp; as you have it set for informational,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You should be able to see the messages now,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jcarvaja&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 23 Oct 2013 20:05:10 GMT</pubDate>
    <dc:creator>Julio Carvajal</dc:creator>
    <dc:date>2013-10-23T20:05:10Z</dc:date>
    <item>
      <title>Help Syslog</title>
      <link>https://community.cisco.com/t5/network-security/help-syslog/m-p/2332566#M310382</link>
      <description>&lt;P&gt;Hi Experts,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Syslog is only showing me hit messages on access-list denying inbound traffic from external (i.e. internet) on outside interface but does not show deny hits from inside traffic going out to any smtp.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i can see increamental hitcounts when i do "show access-list" which tells me the acl is working as should, however i am not able to see that on syslog message.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list inside_access_in line 2 extended deny tcp 10.x.x.x&amp;nbsp; 255.0.0.0 any eq smtp log informational interval 300 (hitcnt=1910) 0x73edd974&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;see output of show run logging&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;firewall01# show run logging&lt;BR /&gt;logging enable&lt;BR /&gt;logging timestamp&lt;BR /&gt;logging emblem&lt;BR /&gt;logging console errors&lt;BR /&gt;logging trap warnings&lt;BR /&gt;logging asdm notifications&lt;BR /&gt;logging queue 0&lt;BR /&gt;logging device-id context-name&lt;BR /&gt;logging host Inside 10.x.x.1&lt;BR /&gt;logging debug-trace&lt;BR /&gt;logging permit-hostdown&lt;BR /&gt;logging class auth console emergencies&lt;BR /&gt;no logging message 313001&lt;BR /&gt;no logging message 313008&lt;BR /&gt;no logging message 710003&lt;BR /&gt;no logging message 106100&lt;BR /&gt;no logging message 302015&lt;BR /&gt;no logging message 302014&lt;BR /&gt;no logging message 302013&lt;BR /&gt;no logging message 302018&lt;BR /&gt;no logging message 302017&lt;BR /&gt;no logging message 302016&lt;BR /&gt;no logging message 302021&lt;BR /&gt;no logging message 302020&lt;BR /&gt;logging message 103012 level alerts&lt;BR /&gt;firewall01#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;can some help please.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 02:55:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-syslog/m-p/2332566#M310382</guid>
      <dc:creator>smetieh001</dc:creator>
      <dc:date>2019-03-12T02:55:31Z</dc:date>
    </item>
    <item>
      <title>Help Syslog</title>
      <link>https://community.cisco.com/t5/network-security/help-syslog/m-p/2332567#M310384</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You have disabled the syslog ID/message that your are looking for with the below command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;no logging message 106100&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You could enter &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;logging message 106100&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To re-enable the syslog ID&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I recall correct you also have some other connection/translation forming log messages disabled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please remember to mark a reply as the correct answer if it answered your question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Feel free to ask more if needed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Oct 2013 17:53:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-syslog/m-p/2332567#M310384</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-10-23T17:53:33Z</dc:date>
    </item>
    <item>
      <title>Help Syslog</title>
      <link>https://community.cisco.com/t5/network-security/help-syslog/m-p/2332568#M310385</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the thing:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;logging host Inside 10.x.x.1&lt;/P&gt;&lt;P&gt;logging trap warnings (l&lt;STRONG&gt;evel 4&lt;/STRONG&gt;)&lt;/P&gt;&lt;P&gt;logging console errors (&lt;STRONG&gt;level 3&lt;/STRONG&gt;)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list inside_access_in line 2 extended deny tcp 10.x.x.x&amp;nbsp; 255.0.0.0 any eq smtp log informational interval 300 (hitcnt=1910) 0x73edd974 (&lt;STRONG&gt;Level 6&lt;/STRONG&gt;)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do u see the problem? Changed the log keyword on the ACL to be level 3 or 4 depending of where you want to send it (4 if you wanna send it to boths)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Jcarvaja&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;follow me on &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://laguiadelnetworking.com"&gt;http://laguiadelnetworking.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Oct 2013 17:54:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-syslog/m-p/2332568#M310385</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-10-23T17:54:54Z</dc:date>
    </item>
    <item>
      <title>Help Syslog</title>
      <link>https://community.cisco.com/t5/network-security/help-syslog/m-p/2332569#M310387</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Seems I remembered the syslog ID wrong&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It was actually 106023 that shows the denied connections.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You should see them in the ASDM with current logging settings. And as Julio mentioned for other destinations of logging you would have to make changes or change the above syslog IDs logging level to something that fits the current levels set.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Oct 2013 18:01:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-syslog/m-p/2332569#M310387</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-10-23T18:01:59Z</dc:date>
    </item>
    <item>
      <title>Help Syslog</title>
      <link>https://community.cisco.com/t5/network-security/help-syslog/m-p/2332570#M310389</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The default syslog message for drops based on ACL applied on access-group is 106023 when you enable log option at the end of an ACL the syslopg option would be 106100.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/acl_logging.html"&gt;http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/acl_logging.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you enter the&amp;nbsp; &lt;STRONG&gt;log&lt;/STRONG&gt; option without any arguments, you enable system log message 106100 at the default level (6) and for the default interval (300 seconds). if you want to change the interval it can be changed up to 1 second but remember that you pass more then one packet per second so it probably won't capture all tries but will most definitively drop all tries based on the deny on the ACL.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you try to change the log message level for 106100 through the next command:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;logging message 106100 level 4&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It will not do it and give you the next information log&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;INFO: Please use the access-list command to change the severity level of this syslog&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Oct 2013 18:21:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-syslog/m-p/2332570#M310389</guid>
      <dc:creator>jumora</dc:creator>
      <dc:date>2013-10-23T18:21:14Z</dc:date>
    </item>
    <item>
      <title>Help Syslog</title>
      <link>https://community.cisco.com/t5/network-security/help-syslog/m-p/2332571#M310391</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Jouni,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your response. The syslogID 106023 is enabled and the logging level set is "warning". I do see syslog messages of ID 106023, however it's only deny acl inbound on my outside interface. I would like to see syslog messages of deny acl hits inbound on my inside interface.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Oct 2013 18:52:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-syslog/m-p/2332571#M310391</guid>
      <dc:creator>smetieh001</dc:creator>
      <dc:date>2013-10-23T18:52:46Z</dc:date>
    </item>
    <item>
      <title>Re: Help Syslog</title>
      <link>https://community.cisco.com/t5/network-security/help-syslog/m-p/2332572#M310393</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I noticed that I actually mistook the correct syslog ID myself before I checked it from the Syslog documentation for ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I guess you have defined a separate level for your ACL rule at the end of the ACL rule? The original post mentions &lt;STRONG&gt;"Informational"&lt;/STRONG&gt; that doesnt match your current levels set in the &lt;STRONG&gt;"logging"&lt;/STRONG&gt; commands.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you had not modified any ACL rules default logging level and had enabled Notifications level logging to the logging destination of your choosing (server, asdm, buffer, etc) , you should see ALL log messages that deny traffic based on ACL rules.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So you you will have to change the logging level of either the actual ACL rules or change the logging level globally for some of the logging destinations you are viewing logs from.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Oct 2013 18:58:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-syslog/m-p/2332572#M310393</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-10-23T18:58:06Z</dc:date>
    </item>
    <item>
      <title>Help Syslog</title>
      <link>https://community.cisco.com/t5/network-security/help-syslog/m-p/2332573#M310396</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just add the log option with the interval defined as one second on the ACE that is denying traffic on tcp/25.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just change delete the ACL and readd it with the correct logging level as Julio asked.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no access-list inside_access_in line 2 extended deny tcp 10.x.x.x&amp;nbsp; 255.0.0.0 any eq smtp log&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list inside_access_in line 2 extended deny tcp 10.x.x.x&amp;nbsp; 255.0.0.0 any eq smtp log 4 interval 1&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Oct 2013 19:06:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-syslog/m-p/2332573#M310396</guid>
      <dc:creator>jumora</dc:creator>
      <dc:date>2013-10-23T19:06:01Z</dc:date>
    </item>
    <item>
      <title>Help Syslog</title>
      <link>https://community.cisco.com/t5/network-security/help-syslog/m-p/2332574#M310398</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It all ends with the correct level definition!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That's it...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Oct 2013 19:10:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-syslog/m-p/2332574#M310398</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-10-23T19:10:21Z</dc:date>
    </item>
    <item>
      <title>Help Syslog</title>
      <link>https://community.cisco.com/t5/network-security/help-syslog/m-p/2332575#M310401</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Thanks all for your response.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;present logging level on deny acl is now warning.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I do see logging messages from 106023 for inbound acl on outside interface however i do not for inbound inside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;however, 106100 is not enabled yet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Question,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Shouldn't 106023 be able to show messages? or i do have to enable 106100? hope my question is not confusing?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Oct 2013 20:00:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-syslog/m-p/2332575#M310401</guid>
      <dc:creator>smetieh001</dc:creator>
      <dc:date>2013-10-23T20:00:14Z</dc:date>
    </item>
    <item>
      <title>Help Syslog</title>
      <link>https://community.cisco.com/t5/network-security/help-syslog/m-p/2332576#M310403</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you have not denied either and by default is enabled. As long&amp;nbsp; as you have it set for informational,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You should be able to see the messages now,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jcarvaja&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Oct 2013 20:05:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-syslog/m-p/2332576#M310403</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-10-23T20:05:10Z</dc:date>
    </item>
    <item>
      <title>Help Syslog</title>
      <link>https://community.cisco.com/t5/network-security/help-syslog/m-p/2332577#M310404</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you enable the keyword log on the ACL for traffic that is logged for what matches the ACL it will only report on syslog ID 106100.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Oct 2013 20:26:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-syslog/m-p/2332577#M310404</guid>
      <dc:creator>jumora</dc:creator>
      <dc:date>2013-10-23T20:26:55Z</dc:date>
    </item>
    <item>
      <title>Help Syslog</title>
      <link>https://community.cisco.com/t5/network-security/help-syslog/m-p/2332578#M310405</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did the information given to you help out for your solution, please let us know?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Oct 2013 01:10:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-syslog/m-p/2332578#M310405</guid>
      <dc:creator>jumora</dc:creator>
      <dc:date>2013-10-29T01:10:53Z</dc:date>
    </item>
    <item>
      <title>Help Syslog</title>
      <link>https://community.cisco.com/t5/network-security/help-syslog/m-p/2332579#M310406</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please update the ticket as resolved or answered so we can close out followup.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Oct 2013 17:54:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-syslog/m-p/2332579#M310406</guid>
      <dc:creator>jumora</dc:creator>
      <dc:date>2013-10-31T17:54:57Z</dc:date>
    </item>
  </channel>
</rss>

