<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Firewall deny not getting logged in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firewall-deny-not-getting-logged/m-p/1609515#M591838</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Jennifer&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We rebooted the FWSM firewall and that solved the issue. If the issue repeats, we are planning to open a TAC case on this.&lt;/P&gt;&lt;P&gt;Thanks for your suggestion&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;S.Balaji&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 17 Feb 2011 13:57:44 GMT</pubDate>
    <dc:creator>balajis27</dc:creator>
    <dc:date>2011-02-17T13:57:44Z</dc:date>
    <item>
      <title>Firewall deny not getting logged</title>
      <link>https://community.cisco.com/t5/network-security/firewall-deny-not-getting-logged/m-p/1609513#M591836</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am facing a strange issue with FWSM firewall rules and need some help on that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On this firewall, we have logging enabled to a log all denies for blocked ports. . This is covered in the last deny statement with port object-group as shown below.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN style="color: #000000; font-family: Arial; "&gt;access-list al_from_labs line 2236 extended deny object-group tcp_udp any any object-group Blocked_Ports log errors interval 300 0x9f5a4bff &lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;In the recent days we found extensive deny logs for the below 6 ports and this was causing the below error message 106101 .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tcp SMTP,tcp 135,tcp 445, tcp netbios-ssn, udp netbios-ns, udp snmp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial; "&gt;106101 The number of ACL log deny-flows has reached limit (number)&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN style="color: #000000; font-family: Arial; "&gt;106101 The number of ACL log deny-flows has reached limit (4096). &lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Already the max configured limit on device is 4096. So we decided to remove logging only for those specifc 6 ports and wanted to still log rest of the denies. So we modified ACL as below&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN style="color: #000000; font-family: Arial; "&gt;ddddd# sh access-list al_from_labs | in deny&lt;BR /&gt;access-list al_from_labs line 2227 extended deny tcp any any eq smtp (hitcnt=29954) 0xf62aaca9&lt;BR /&gt;access-list al_from_labs line 2228 extended deny tcp any any eq 135 (hitcnt=2127) 0xc8773775&lt;BR /&gt;access-list al_from_labs line 2229 extended deny tcp any any eq 445 (hitcnt=2617) 0x9ad56a8f&lt;BR /&gt;access-list al_from_labs line 2230 extended deny tcp any any eq netbios-ssn (hitcnt=888) 0x9258206&lt;BR /&gt;access-list al_from_labs line 2231 extended deny udp any any eq netbios-ns (hitcnt=8670) 0x5fad9aa0&lt;BR /&gt;access-list al_from_labs line 2232 extended deny udp any any eq snmp (hitcnt=532) 0xfe3a0d52&lt;BR /&gt;access-list al_from_labs line 2236 extended deny object-group tcp_udp any any object-group Blocked_Ports log errors interval 300 0x9f5a4bff &lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please see above where we removed logging for those specific 6 denies and moved it above the last deny rule.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Issue:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;====&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;After we modified the acl entries as above, we see strangely that none of the denies are getting logged to the syslog server. So absolutely logging gets stopped. This is confusing becos we only wanted the firewall not to log for those specific 6 ports but now access attempt to other ports also is not getting logged.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please let us know what might be the cause of the issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 19:50:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-deny-not-getting-logged/m-p/1609513#M591836</guid>
      <dc:creator>balajis27</dc:creator>
      <dc:date>2019-03-11T19:50:11Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall deny not getting logged</title>
      <link>https://community.cisco.com/t5/network-security/firewall-deny-not-getting-logged/m-p/1609514#M591837</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My suggestion would be to reload the FWSM to clear the cached flow.&lt;/P&gt;&lt;P&gt;However, if you would like to know the reason why it's not working as it should, I would suggest that you open a TAC case so the issue can be investigated further.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Feb 2011 06:26:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-deny-not-getting-logged/m-p/1609514#M591837</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2011-02-14T06:26:16Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall deny not getting logged</title>
      <link>https://community.cisco.com/t5/network-security/firewall-deny-not-getting-logged/m-p/1609515#M591838</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Jennifer&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We rebooted the FWSM firewall and that solved the issue. If the issue repeats, we are planning to open a TAC case on this.&lt;/P&gt;&lt;P&gt;Thanks for your suggestion&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;S.Balaji&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Feb 2011 13:57:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-deny-not-getting-logged/m-p/1609515#M591838</guid>
      <dc:creator>balajis27</dc:creator>
      <dc:date>2011-02-17T13:57:44Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall deny not getting logged</title>
      <link>https://community.cisco.com/t5/network-security/firewall-deny-not-getting-logged/m-p/1609516#M591839</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Excellent, and it's great to hear.&lt;/P&gt;&lt;P&gt;Please kindly mark the post answered so others can learn from your post. Thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Feb 2011 22:35:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-deny-not-getting-logged/m-p/1609516#M591839</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2011-02-17T22:35:56Z</dc:date>
    </item>
  </channel>
</rss>

