<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: asa log in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-log/m-p/1619757#M595282</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;1. The level of logging is different for ASDM and buffer. That is why the logging outputs in ASDM and buffer (sho log) will not be the same. One will be a 'subset' of the other.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. This would depend entirely on your requirement. E.g., if most traffic is through IPSec then more BW should be recseved for this traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;Paps&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 05 Jan 2011 13:19:48 GMT</pubDate>
    <dc:creator>padatta</dc:creator>
    <dc:date>2011-01-05T13:19:48Z</dc:date>
    <item>
      <title>asa log</title>
      <link>https://community.cisco.com/t5/network-security/asa-log/m-p/1619756#M595281</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Few questions on ASA:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. one of asa&amp;nbsp; has logging enabled for warning &amp;amp; information message.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; logging enable&lt;/P&gt;&lt;P&gt;logging buffered warnings&lt;/P&gt;&lt;P&gt;logging asdm informational&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;when asdm logs are seen, it shows normal teardown etc. for traffic. but sh log gives lot of different logs, below is one of them:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; %ASA-2-106001: Inbound TCP connection denied from 45.34.115.88/3160 to 202.88.179.15/445 flags SYN&amp;nbsp; on interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;why are these logs appearing seperately &amp;amp; is it the correct way of syslog configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. diagram is:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; remote branch - internet - asa - 3845 router - local office&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; remote branch needs data from local office and vice-versa, this is done with ipsec, which is between remote branch &amp;amp; router. plan is to do shift this frm router to asa. i.e remote branch to asa will have ipsec points &amp;amp; users on both sides will use it for data.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;on the router , we feel that ipsec is using large bandwidth from our internet ( 5M ),router to local office has 4M capacity. i know asa can be used for police function.&lt;/P&gt;&lt;P&gt;will it be&amp;nbsp; a good solution if set bandwidth of 1M is put on asa for it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 19:30:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-log/m-p/1619756#M595281</guid>
      <dc:creator>suthomas1</dc:creator>
      <dc:date>2019-03-11T19:30:28Z</dc:date>
    </item>
    <item>
      <title>Re: asa log</title>
      <link>https://community.cisco.com/t5/network-security/asa-log/m-p/1619757#M595282</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;1. The level of logging is different for ASDM and buffer. That is why the logging outputs in ASDM and buffer (sho log) will not be the same. One will be a 'subset' of the other.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. This would depend entirely on your requirement. E.g., if most traffic is through IPSec then more BW should be recseved for this traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;Paps&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Jan 2011 13:19:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-log/m-p/1619757#M595282</guid>
      <dc:creator>padatta</dc:creator>
      <dc:date>2011-01-05T13:19:48Z</dc:date>
    </item>
    <item>
      <title>Re: asa log</title>
      <link>https://community.cisco.com/t5/network-security/asa-log/m-p/1619758#M595283</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;1. what should be the correct logging level for both to be same or so not to have 2 different log outputs &amp;amp; only 1 common log.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. oracle tcp traffic between 2 hosts on both sites will be major use on this ipsec. either can initiate the connection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;please help.&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Jan 2011 13:42:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-log/m-p/1619758#M595283</guid>
      <dc:creator>suthomas1</dc:creator>
      <dc:date>2011-01-05T13:42:25Z</dc:date>
    </item>
    <item>
      <title>Re: asa log</title>
      <link>https://community.cisco.com/t5/network-security/asa-log/m-p/1619759#M595285</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is no correct way of logging. It is how much information you like to see which is entirely upto the requirement. These do not have to be the same.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We suggest not to send debug level logs to the console as it is at 9600 bps. As far as monitor, buffer, trap and asdm is concerned you can change it to any level.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When we troubleshoot from command line we usually crank up the buffer log to debug&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;conf t&lt;/P&gt;&lt;P&gt;logging on&lt;/P&gt;&lt;P&gt;logging buffered 7&lt;/P&gt;&lt;P&gt;exit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;People also use ftp server to send the buffer-wrap to and also send certain messages or range of messages via e-mail.&lt;/P&gt;&lt;P&gt;Techically you can have&lt;/P&gt;&lt;P&gt;logging on&lt;/P&gt;&lt;P&gt;logging buffered 7&lt;/P&gt;&lt;P&gt;logging console 1&lt;/P&gt;&lt;P&gt;logging monitor 2&lt;/P&gt;&lt;P&gt;logging trap 6&lt;/P&gt;&lt;P&gt;logging host inside 1.1.1.1&lt;/P&gt;&lt;P&gt;logging asdm 5&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;You can check the command ref. here: &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa82/command/reference/l2.html#wp1772754"&gt;http://www.cisco.com/en/US/docs/security/asa/asa82/command/reference/l2.html#wp1772754&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2. Yes you can configure policing and prioritizing. Pls. refer this QoS link: &lt;/SPAN&gt;&lt;A href="https://community.cisco.com/docs/DOC-1230"&gt;https://supportforums.cisco.com/docs/DOC-1230&lt;/A&gt;&lt;/P&gt;&lt;P&gt;That has step by step instructions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Jan 2011 14:27:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-log/m-p/1619759#M595285</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2011-01-05T14:27:09Z</dc:date>
    </item>
    <item>
      <title>Re: asa log</title>
      <link>https://community.cisco.com/t5/network-security/asa-log/m-p/1619760#M595288</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks KS. lastly, on the qos part, when policy is put on outside, does it police for both inbound &amp;amp; outbound?&lt;/P&gt;&lt;P&gt; can i put an acl like; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; acl oracle line 1 extended permit tcp host 192.168.100.2 host 192.168.200.5 eq 1445&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; acl oracle line 2 extended permit tcp host 192.168.200.5 host 192.168.100.2 eq 1445&lt;/P&gt;&lt;P&gt;and then apply this to class for limit on both ways traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Jan 2011 15:02:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-log/m-p/1619760#M595288</guid>
      <dc:creator>suthomas1</dc:creator>
      <dc:date>2011-01-05T15:02:00Z</dc:date>
    </item>
    <item>
      <title>Re: asa log</title>
      <link>https://community.cisco.com/t5/network-security/asa-log/m-p/1619761#M595290</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No. ACL is just the interesting traffic that you want policed. Police input and/or police out should be used.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="content"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="pB1_Body1"&gt;The &lt;STRONG class="cCN_CmdName"&gt;input &lt;/STRONG&gt;keyword enables policing of traffic flowing in the input direction.&lt;/P&gt;&lt;A name="wp1078093"&gt;&lt;/A&gt;&lt;P class="pB1_Body1"&gt;The &lt;STRONG class="cKeyword"&gt;output &lt;/STRONG&gt;keyword enables policing of traffic flowing in the output direction.&lt;/P&gt;&lt;P class="pB1_Body1"&gt;&lt;/P&gt;&lt;P class="pB1_Body1"&gt;&lt;SPAN&gt;You can refer this link (step 3): &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/conns_qos.html#wp1071334"&gt;http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/conns_qos.html#wp1071334&lt;/A&gt;&lt;/P&gt;&lt;P class="pB1_Body1"&gt;&lt;/P&gt;&lt;P class="pB1_Body1"&gt;-KS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Jan 2011 15:13:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-log/m-p/1619761#M595290</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2011-01-05T15:13:36Z</dc:date>
    </item>
    <item>
      <title>Re: asa log</title>
      <link>https://community.cisco.com/t5/network-security/asa-log/m-p/1619762#M595292</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;so if the traffic flows&amp;nbsp; from remote site to locate site &amp;amp; vice versa&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; ( remote branch - internet - asa - 3845 router - local office ) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;it would be more proper to apply it outbound on outside of asa. please correct if otherwise.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Jan 2011 15:34:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-log/m-p/1619762#M595292</guid>
      <dc:creator>suthomas1</dc:creator>
      <dc:date>2011-01-05T15:34:10Z</dc:date>
    </item>
    <item>
      <title>Re: asa log</title>
      <link>https://community.cisco.com/t5/network-security/asa-log/m-p/1619763#M595293</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Correct. I agree.&lt;/P&gt;&lt;P&gt;Policy outside - would be appropriate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Jan 2011 15:38:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-log/m-p/1619763#M595293</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2011-01-05T15:38:54Z</dc:date>
    </item>
  </channel>
</rss>

