<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Log dropped packets to syslog server (PIX 506 v6.3) in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/log-dropped-packets-to-syslog-server-pix-506-v6-3/m-p/579524#M527605</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Regarding the behaviour from the pix, it looks to me there is no logging problem and syslogs are not lost. You can verify this with a "show log queue" on the pix.&lt;/P&gt;&lt;P&gt;Instead, check if the "denied IP" you use to make tests is really routed to the pix, and not dropped somewhere else on the network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;Mike &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 15 Feb 2006 16:42:06 GMT</pubDate>
    <dc:creator>mpalardy</dc:creator>
    <dc:date>2006-02-15T16:42:06Z</dc:date>
    <item>
      <title>Log dropped packets to syslog server (PIX 506 v6.3)</title>
      <link>https://community.cisco.com/t5/network-security/log-dropped-packets-to-syslog-server-pix-506-v6-3/m-p/579523#M527603</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am new at setting up PIX firewall.. Hope that someone would give me some hints on how to log dropped packets to my syslog server. Here is what i have setup and tested..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) I manage to setup remote logging for my syslog server, i could see PIX firewall logs appearing in /var/log/messages in the syslog server...&lt;/P&gt;&lt;P&gt;Feb 15 18:14:33 firewall1 Feb 15 2006 02:12:14: %PIX-5-111008: User 'enable_1' executed the 'enable' command.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) Have added the following in the access_list...&lt;/P&gt;&lt;P&gt;access-list PERMIT_IN deny ip any any log&lt;/P&gt;&lt;P&gt;access-group PERMIT_IN in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3) Have set buffered logging to 6&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4) Tried to telnet from a "denied" IP. However no logs appear in the syslog server and the dropped packet also did not appear in "show logging".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is "show logging" output...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Syslog logging: enabled&lt;/P&gt;&lt;P&gt;    Facility: 20&lt;/P&gt;&lt;P&gt;    Timestamp logging: enabled&lt;/P&gt;&lt;P&gt;    Standby logging: disabled&lt;/P&gt;&lt;P&gt;    Console logging: disabled&lt;/P&gt;&lt;P&gt;    Monitor logging: disabled&lt;/P&gt;&lt;P&gt;    Buffer logging: level errors, 126 messages logged&lt;/P&gt;&lt;P&gt;    Trap logging: level notifications, 136 messages logged&lt;/P&gt;&lt;P&gt;        Logging to inside 10.26.10.100&lt;/P&gt;&lt;P&gt;    History logging: disabled&lt;/P&gt;&lt;P&gt;    Device ID: disabled&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pls let me know if i have missed out something. Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;thamch&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 08:42:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/log-dropped-packets-to-syslog-server-pix-506-v6-3/m-p/579523#M527603</guid>
      <dc:creator>thamchunhong</dc:creator>
      <dc:date>2020-02-21T08:42:49Z</dc:date>
    </item>
    <item>
      <title>Re: Log dropped packets to syslog server (PIX 506 v6.3)</title>
      <link>https://community.cisco.com/t5/network-security/log-dropped-packets-to-syslog-server-pix-506-v6-3/m-p/579524#M527605</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Regarding the behaviour from the pix, it looks to me there is no logging problem and syslogs are not lost. You can verify this with a "show log queue" on the pix.&lt;/P&gt;&lt;P&gt;Instead, check if the "denied IP" you use to make tests is really routed to the pix, and not dropped somewhere else on the network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;Mike &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Feb 2006 16:42:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/log-dropped-packets-to-syslog-server-pix-506-v6-3/m-p/579524#M527605</guid>
      <dc:creator>mpalardy</dc:creator>
      <dc:date>2006-02-15T16:42:06Z</dc:date>
    </item>
  </channel>
</rss>

