<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA drops syslog traffic in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-drops-syslog-traffic/m-p/1976819#M440859</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well, all these VM, XenServer and ASA are on the same subnet right? Mask is /24?&lt;/P&gt;&lt;P&gt;If so, why are the packets going between 1.200 to 1.210 going to the ASA?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If these are on different subnet then the topology should look like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;VM---ASA---Syslog_Server&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And, you need to provide translation for the VM host.&lt;/P&gt;&lt;P&gt;static (inside,outside) VM_IP VM_IP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Kureli&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 18 Jun 2012 21:37:31 GMT</pubDate>
    <dc:creator>Kureli Sankar</dc:creator>
    <dc:date>2012-06-18T21:37:31Z</dc:date>
    <item>
      <title>ASA drops syslog traffic</title>
      <link>https://community.cisco.com/t5/network-security/asa-drops-syslog-traffic/m-p/1976818#M440858</link>
      <description>&lt;P&gt;Ok, I can't for the life of my figure out why &lt;STRONG&gt;internal&lt;/STRONG&gt; syslog traffic would be dropped at the firewall.&amp;nbsp; I've come across a few support forums with comments like 'disable the specific syslog error, etc.' however this does not fix my problem.&amp;nbsp; I need the syslog messages from my Citrix VM Servers to reach the syslog server and the firewall is dropping them for some reason:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The syslog error that gets logged:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;%ASA-2-106006: Deny inbound UDP from 192.168.1.200/514 to 192.168.1.210/514 on interface inside &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is my current lab setup:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ubuntu (VM)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; --&amp;gt; XenServer&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; --&amp;gt; ASA 5505&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;(192.168.1.201)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (192.168.1.200)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (192.168.1.1)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have tons of hits on rule #2, none on rule #1 for my inside interface access list:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;1. access-list inside_access_in extended permit udp any any eq syslog log notifications &lt;/STRONG&gt;&lt;EM&gt;(put this one in for test... doesn't get any hits)&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;2. access-list inside_access_in extended permit ip any any log &lt;/STRONG&gt;&lt;EM&gt;(this is the rule that should allow all internal traffic, right?)&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is the output from 'show logging'&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Syslog logging: enabled&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Facility: 16&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Timestamp logging: enabled&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Standby logging: disabled&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Debug-trace logging: disabled&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Console logging: disabled&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Monitor logging: disabled&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Buffer logging: disabled&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Trap logging: level critical, facility 16, 970565 messages logged&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Logging to inside 192.168.1.210 errors: 70&amp;nbsp; dropped: 1162&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Permit-hostdown logging: disabled&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; History logging: disabled&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Device ID: hostname "asa1"&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Mail logging: disabled&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ASDM logging: level warnings, 4035521 messages logged&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 23:19:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-drops-syslog-traffic/m-p/1976818#M440858</guid>
      <dc:creator>justinfarmer</dc:creator>
      <dc:date>2019-03-11T23:19:05Z</dc:date>
    </item>
    <item>
      <title>ASA drops syslog traffic</title>
      <link>https://community.cisco.com/t5/network-security/asa-drops-syslog-traffic/m-p/1976819#M440859</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well, all these VM, XenServer and ASA are on the same subnet right? Mask is /24?&lt;/P&gt;&lt;P&gt;If so, why are the packets going between 1.200 to 1.210 going to the ASA?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If these are on different subnet then the topology should look like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;VM---ASA---Syslog_Server&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And, you need to provide translation for the VM host.&lt;/P&gt;&lt;P&gt;static (inside,outside) VM_IP VM_IP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Kureli&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Jun 2012 21:37:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-drops-syslog-traffic/m-p/1976819#M440859</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2012-06-18T21:37:31Z</dc:date>
    </item>
  </channel>
</rss>

