<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA VPN Logging Issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-vpn-logging-issue/m-p/1938263#M458581</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Razi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm not sure why you can't see 722022 and 746012 in the debug level logs. However, unless I am mistaken,you should be able to change logs 746012 and 734003 to informational using the same command you are using for those other messages. You might try this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;logging message 746012 informational&lt;/P&gt;&lt;P&gt;logging message 734003 informational&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Joey&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 02 Mar 2012 19:07:39 GMT</pubDate>
    <dc:creator>johuggin</dc:creator>
    <dc:date>2012-03-02T19:07:39Z</dc:date>
    <item>
      <title>ASA VPN Logging Issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-vpn-logging-issue/m-p/1938260#M458578</link>
      <description>&lt;P&gt;Hello experts,&lt;/P&gt;&lt;P&gt;I have upgraded my ASA5540 form 8.2(2) to 8.4(2) and I have run into this logging issue.&lt;/P&gt;&lt;P&gt;previously I was logging the message ID: 713906 and could get this information:&lt;/P&gt;&lt;P&gt;group name, public address, assigned local address, username which identifies all the elements of a tunnel establishment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As I upgraded to 8.4(2) I have lost this logging capability. I have tried to use different logging message ID alternatives like 722022, 722051 without any luck. I configured the message IDs and just they are not being logged. here is my config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;logging enable&lt;/P&gt;&lt;P&gt;logging facility 22&lt;/P&gt;&lt;P&gt;logging queue 1024&lt;/P&gt;&lt;P&gt;logging device-id hostname&lt;/P&gt;&lt;P&gt;logging buffered 10000000&lt;/P&gt;&lt;P&gt;logging message 722051 level debugging&lt;/P&gt;&lt;P&gt;logging message 713906 level debugging&lt;/P&gt;&lt;P&gt;logging message 713050 level debugging&lt;/P&gt;&lt;P&gt;logging message 715053 level debugging&lt;/P&gt;&lt;P&gt;logging message 715019 level debugging&lt;/P&gt;&lt;P&gt;logging message 713906 level debugging&lt;/P&gt;&lt;P&gt;logging message 713184 level debugging&lt;/P&gt;&lt;P&gt;logging message 113019 level debugging&lt;/P&gt;&lt;P&gt;logging message 113004 level debugging&lt;/P&gt;&lt;P&gt;logging message 113005 level debugging&lt;/P&gt;&lt;P&gt;logging message 713052 level debugging&lt;/P&gt;&lt;P&gt;logging message 106015 level debugging&lt;/P&gt;&lt;P&gt;logging message 302013 level debugging&lt;/P&gt;&lt;P&gt;logging message 302016 level debugging&lt;/P&gt;&lt;P&gt;logging message 302014 level debugging&lt;/P&gt;&lt;P&gt;logging message 750006 level debugging&lt;/P&gt;&lt;P&gt;logging message 722022 level debugging&lt;/P&gt;&lt;P&gt;logging message 737026 level debugging&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I see lots of lines being logged for connection etablishment, but not the above logs which I am interested in. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am interested to have at least 'username, local ip address, at the time the session is established all together in one line. I can see many lines for 302013, 302014, 302016 for different connections, but I am more intereseted in the start of the session.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And please note I am using pure ipsec both IKEV1 and IKEV2 with cisco vpn client as well as cisco anyconnect. I am NOT using ssl vpn.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Razi&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 22:37:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-vpn-logging-issue/m-p/1938260#M458578</guid>
      <dc:creator>rdianat</dc:creator>
      <dc:date>2019-03-11T22:37:33Z</dc:date>
    </item>
    <item>
      <title>ASA VPN Logging Issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-vpn-logging-issue/m-p/1938261#M458579</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Razi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you seeing any debug level logs? What are the level of logs which you are seeing? Can you give us an output of a &lt;STRONG&gt;'show logging messsage&lt;/STRONG&gt; &lt;STRONG&gt;722022'&lt;/STRONG&gt;?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Mar 2012 18:49:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-vpn-logging-issue/m-p/1938261#M458579</guid>
      <dc:creator>johuggin</dc:creator>
      <dc:date>2012-03-01T18:49:37Z</dc:date>
    </item>
    <item>
      <title>ASA VPN Logging Issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-vpn-logging-issue/m-p/1938262#M458580</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Yes, I see the debug level logs but nothing for 722022.&lt;/P&gt;&lt;P&gt;tst-vpn(config)# sh logg mess 722022&lt;/P&gt;&lt;P&gt;syslog 722022: default-level informational, current-level debugging (enabled)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now I found the message ID 746012 and 734003 could be an acceptable solution, but the problem is for these two messages to be logged I have to enable logging buffered debugging". When I enable buffered debug logging, the buffer gets full immediately and I get lots of undesired logs. Is there any other message ID which can work in informational (level 6) and give me the same information as in 746012 or 722022?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Razi&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Mar 2012 20:59:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-vpn-logging-issue/m-p/1938262#M458580</guid>
      <dc:creator>rdianat</dc:creator>
      <dc:date>2012-03-01T20:59:42Z</dc:date>
    </item>
    <item>
      <title>ASA VPN Logging Issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-vpn-logging-issue/m-p/1938263#M458581</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Razi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm not sure why you can't see 722022 and 746012 in the debug level logs. However, unless I am mistaken,you should be able to change logs 746012 and 734003 to informational using the same command you are using for those other messages. You might try this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;logging message 746012 informational&lt;/P&gt;&lt;P&gt;logging message 734003 informational&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Joey&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Mar 2012 19:07:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-vpn-logging-issue/m-p/1938263#M458581</guid>
      <dc:creator>johuggin</dc:creator>
      <dc:date>2012-03-02T19:07:39Z</dc:date>
    </item>
    <item>
      <title>ASA VPN Logging Issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-vpn-logging-issue/m-p/1938264#M458582</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Joey,&lt;/P&gt;&lt;P&gt;I CAN see 746012, but only if I have enabled debug logging " logging buffered debugging"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did the commands you have mentioned:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;logging message 746012 informational&lt;/P&gt;&lt;P&gt;logging message 734003 informational&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;by doing this I can not see these messages, but if I do "logging buffered debugging" then I can see these messages. if a message is generated in debug level, we can not change it to informational level by "informational" keyword. This is what I thought and that is what I see after configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any other thought?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Razi&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Mar 2012 20:21:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-vpn-logging-issue/m-p/1938264#M458582</guid>
      <dc:creator>rdianat</dc:creator>
      <dc:date>2012-03-02T20:21:13Z</dc:date>
    </item>
    <item>
      <title>Re: ASA VPN Logging Issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-vpn-logging-issue/m-p/1938265#M458583</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There&amp;nbsp;are&amp;nbsp;multiple&amp;nbsp;issues&amp;nbsp;in&amp;nbsp;this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1.&amp;nbsp;The&amp;nbsp;logs&amp;nbsp;don't&amp;nbsp;contain&amp;nbsp;all&amp;nbsp;the&amp;nbsp;required&amp;nbsp;information.&lt;/P&gt;&lt;P&gt;2.&amp;nbsp;There&amp;nbsp;are&amp;nbsp;multiple&amp;nbsp;logs&amp;nbsp;with&amp;nbsp;information&amp;nbsp;of&amp;nbsp;interest.&lt;/P&gt;&lt;P&gt;3.&amp;nbsp;The&amp;nbsp;same&amp;nbsp;log&amp;nbsp;appears&amp;nbsp;more&amp;nbsp;then&amp;nbsp;once&amp;nbsp;at&amp;nbsp;the&amp;nbsp;same&amp;nbsp;time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Filed&amp;nbsp;a&amp;nbsp;bug&amp;nbsp;to&amp;nbsp;resolve&amp;nbsp;the&amp;nbsp;same&amp;nbsp;log&amp;nbsp;appearing&amp;nbsp;twice.&amp;nbsp;The&amp;nbsp;bug&amp;nbsp;ID&amp;nbsp;is&amp;nbsp;:&amp;nbsp;CSCtz01680.&amp;nbsp;The&amp;nbsp;bug&amp;nbsp;is&amp;nbsp;resolved&amp;nbsp;and&amp;nbsp;needs&amp;nbsp;to&amp;nbsp;be&amp;nbsp;incorporated&amp;nbsp;in&amp;nbsp;one&amp;nbsp;of&amp;nbsp;the&amp;nbsp;future&amp;nbsp;releases.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Filed&amp;nbsp;an&amp;nbsp;enhancement&amp;nbsp;request&amp;nbsp;CSCtz01714&amp;nbsp;to&amp;nbsp;resolve&amp;nbsp;the&amp;nbsp;logging&amp;nbsp;information&amp;nbsp;issue.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Apr 2012 16:55:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-vpn-logging-issue/m-p/1938265#M458583</guid>
      <dc:creator>Kamal Malhotra</dc:creator>
      <dc:date>2012-04-27T16:55:50Z</dc:date>
    </item>
  </channel>
</rss>

