<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA 5510 real time logs showing incorrect ports in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5510-real-time-logs-showing-incorrect-ports/m-p/2069301#M403216</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you copy paste example log messages from either the ASDM or the CLI of the ASA?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You sure you have not disabled any syslog messages IDs or made some other changes to logging?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you sure you are not watching the log lines about PAT translations? They will have a high end port as the source/destination &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;They start with the "Built dynamic TCP translation from" etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 18 Oct 2012 12:06:15 GMT</pubDate>
    <dc:creator>Jouni Forss</dc:creator>
    <dc:date>2012-10-18T12:06:15Z</dc:date>
    <item>
      <title>ASA 5510 real time logs showing incorrect ports</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-real-time-logs-showing-incorrect-ports/m-p/2069300#M403215</link>
      <description>&lt;P&gt;I have an issue on an ASA 5510 that I have noticed today, when I am using the log viewer all of the information recorded only shows the high end source and destination ports.&amp;nbsp; For example&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Source IP 10.10.4.69 &lt;/P&gt;&lt;P&gt;Source Port 59886&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Destination IP 8.8.8.8&lt;/P&gt;&lt;P&gt;Destination Port 59866&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So what seems to be happening is that I am seeing only half of the connection in the log viewer, I see the side with the high end ports and not the side with the ports the application uses, this example was done with a ping.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All my services are working correctly and the client sending the ping gets the response expected, it just seems I have lost the logging display?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kyle&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 00:11:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-real-time-logs-showing-incorrect-ports/m-p/2069300#M403215</guid>
      <dc:creator>kyle.heath</dc:creator>
      <dc:date>2019-03-12T00:11:05Z</dc:date>
    </item>
    <item>
      <title>ASA 5510 real time logs showing incorrect ports</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-real-time-logs-showing-incorrect-ports/m-p/2069301#M403216</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you copy paste example log messages from either the ASDM or the CLI of the ASA?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You sure you have not disabled any syslog messages IDs or made some other changes to logging?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you sure you are not watching the log lines about PAT translations? They will have a high end port as the source/destination &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;They start with the "Built dynamic TCP translation from" etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Oct 2012 12:06:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-real-time-logs-showing-incorrect-ports/m-p/2069301#M403216</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2012-10-18T12:06:15Z</dc:date>
    </item>
    <item>
      <title>ASA 5510 real time logs showing incorrect ports</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-real-time-logs-showing-incorrect-ports/m-p/2069302#M403217</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jouni&amp;nbsp; I think you are on to something here. Yes the logging starts with the Built dynamic TCP translation from so I think I am seeing the PAT here.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there something that I am missing in the logging to see the NAT instead?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kyle&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Oct 2012 16:11:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-real-time-logs-showing-incorrect-ports/m-p/2069302#M403217</guid>
      <dc:creator>kyle.heath</dc:creator>
      <dc:date>2012-10-18T16:11:19Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 real time logs showing incorrect ports</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-real-time-logs-showing-incorrect-ports/m-p/2069303#M403218</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Syslog IDs for the log messages that have to do with forming/building TCP/UDP connections should be &lt;STRONG&gt;302013-302016&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Syslog IDs for the log messages that have to do with forming/building translations should be &lt;STRONG&gt;305011-305012&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By default if you had only configured the logging levels like this&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;logging buffered informational&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;logging asdm informational&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;logging trap informational&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You should always see log messages of the formed connections and translations both. I guess in alot of situations people only use &lt;STRONG&gt;"notifications"&lt;/STRONG&gt; logging level that generally just shows connections that have been blocked by the firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can't think of many reasons at the moment why you wouldnt see log messages related to forming the connections if you have the above logging level set&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One possiblity is that you have (or someone else) has configured the ASA so that those logging messages have been disabled. This should be verifiable by issuing the command "show run logging" and looking for commands that start with &lt;STRONG&gt;"no"&lt;/STRONG&gt; parameter and include the syslog IDs I mentioned earlier.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Other thing could be that you have access-list statements in the interface access-list that have modified logging settings at the end. I guess in this it might be in some access-list rule that permits all the traffic and the logging level is set to something that is out of the range of the setting you have configured with the above "logging" commands.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can't think of anything else at the moment&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Oct 2012 16:42:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-real-time-logs-showing-incorrect-ports/m-p/2069303#M403218</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2012-10-18T16:42:16Z</dc:date>
    </item>
    <item>
      <title>ASA 5510 real time logs showing incorrect ports</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-real-time-logs-showing-incorrect-ports/m-p/2069304#M403219</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jouni&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you very much, it was indeed the syslog ID that were disabled, the exact range you were mentioning.&amp;nbsp; I enabled these again and I can see the logging I need.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Oct 2012 08:39:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-real-time-logs-showing-incorrect-ports/m-p/2069304#M403219</guid>
      <dc:creator>kyle.heath</dc:creator>
      <dc:date>2012-10-19T08:39:46Z</dc:date>
    </item>
  </channel>
</rss>

