<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can the ASA 'sla monitor' log state changes to the log buffe in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/can-the-asa-sla-monitor-log-state-changes-to-the-log-buffer/m-p/1499490#M658878</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think the below is what you are looking for:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa72/system/message/logmsgs.html#wp3741861"&gt;http://www.cisco.com/en/US/docs/security/asa/asa72/system/message/logmsgs.html#wp3741861&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can also look at the below link:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/cgi-bin/Support/Errordecoder/index.cgi?action=search&amp;amp;locale=en&amp;amp;index=all&amp;amp;query=ASA-6-622001&amp;amp;counter=0&amp;amp;paging=5&amp;amp;links=reference&amp;amp;sa=Submit"&gt;http://www.cisco.com/cgi-bin/Support/Errordecoder/index.cgi?action=search&amp;amp;locale=en&amp;amp;index=all&amp;amp;query=ASA-6-622001&amp;amp;counter=0&amp;amp;paging=5&amp;amp;links=reference&amp;amp;sa=Submit&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can look at the below document for all the logs that are produced when tacking succeeds and when it fails:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00806e880b.shtml#debug"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00806e880b.shtml#debug&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if this helps. All the best!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Prapanch&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 30 Aug 2010 04:33:41 GMT</pubDate>
    <dc:creator>praprama</dc:creator>
    <dc:date>2010-08-30T04:33:41Z</dc:date>
    <item>
      <title>Can the ASA 'sla monitor' log state changes to the log buffer?!</title>
      <link>https://community.cisco.com/t5/network-security/can-the-asa-sla-monitor-log-state-changes-to-the-log-buffer/m-p/1499488#M658876</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Questions:&lt;/STRONG&gt;&amp;nbsp; Does anyone know if "sla monitor" can log its state&amp;nbsp; changes?&amp;nbsp; If not now, is it planned in a future release?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Background:&lt;/STRONG&gt;&amp;nbsp; Since version &lt;SPAN class="content"&gt;7.2(1), the ASA firewall has a "sla monitor" feature to monitor the availability of remote IP addresses, eg&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; sla monitor 10&lt;BR /&gt;&amp;nbsp;&amp;nbsp; type echo protocol ipIcmpEcho 10.1.10.1 interface outside&lt;BR /&gt;&amp;nbsp;&amp;nbsp; num-packets 3&lt;BR /&gt;&amp;nbsp;&amp;nbsp; frequency 10&lt;BR /&gt;&amp;nbsp; sla monitor schedule 10 life forever start-time now&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="content"&gt;which can then be applied to make routing changes (using "track" to add/remove) routes, eg:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; route outside 0.0.0.0 0.0.0.0 10.1.1.1 1 track 1&lt;BR /&gt;&amp;nbsp; route outsid2 0.0.0.0 0.0.0.0 10.2.2.2 250&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The running state can be manually seen with:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; anyASAfirewall# show sla monitor operational-state &lt;BR /&gt;&amp;nbsp; Entry number: 10&lt;BR /&gt;&amp;nbsp; ...&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; Latest operation return code: OK&lt;BR /&gt;&amp;nbsp; ...&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Other than debug commands, the state changes are not logged, nor does there appear any respective logging commands.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ability for sla monitor to log state changes would be a very useful feature, particularly in determining when *all* events occured and action was taken.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="content"&gt;Thanks in advance&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Jason&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 18:32:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-the-asa-sla-monitor-log-state-changes-to-the-log-buffer/m-p/1499488#M658876</guid>
      <dc:creator>j.irwin</dc:creator>
      <dc:date>2019-03-11T18:32:04Z</dc:date>
    </item>
    <item>
      <title>Re: Can the ASA 'sla monitor' log state changes to the log buffe</title>
      <link>https://community.cisco.com/t5/network-security/can-the-asa-sla-monitor-log-state-changes-to-the-log-buffer/m-p/1499489#M658877</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can try syslog message 622001. It notifies whenever there is an&lt;/P&gt;&lt;P&gt;addition/deletion of the tracked route.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;http://www.cisco.com/en/US/docs/security/asa/asa82/system/message/logmsgs.ht&lt;/P&gt;&lt;P&gt;ml#wp4774896&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NT&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Aug 2010 04:26:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-the-asa-sla-monitor-log-state-changes-to-the-log-buffer/m-p/1499489#M658877</guid>
      <dc:creator>Nagaraja Thanthry</dc:creator>
      <dc:date>2010-08-30T04:26:52Z</dc:date>
    </item>
    <item>
      <title>Re: Can the ASA 'sla monitor' log state changes to the log buffe</title>
      <link>https://community.cisco.com/t5/network-security/can-the-asa-sla-monitor-log-state-changes-to-the-log-buffer/m-p/1499490#M658878</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think the below is what you are looking for:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa72/system/message/logmsgs.html#wp3741861"&gt;http://www.cisco.com/en/US/docs/security/asa/asa72/system/message/logmsgs.html#wp3741861&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can also look at the below link:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/cgi-bin/Support/Errordecoder/index.cgi?action=search&amp;amp;locale=en&amp;amp;index=all&amp;amp;query=ASA-6-622001&amp;amp;counter=0&amp;amp;paging=5&amp;amp;links=reference&amp;amp;sa=Submit"&gt;http://www.cisco.com/cgi-bin/Support/Errordecoder/index.cgi?action=search&amp;amp;locale=en&amp;amp;index=all&amp;amp;query=ASA-6-622001&amp;amp;counter=0&amp;amp;paging=5&amp;amp;links=reference&amp;amp;sa=Submit&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can look at the below document for all the logs that are produced when tacking succeeds and when it fails:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00806e880b.shtml#debug"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00806e880b.shtml#debug&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if this helps. All the best!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Prapanch&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Aug 2010 04:33:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-the-asa-sla-monitor-log-state-changes-to-the-log-buffer/m-p/1499490#M658878</guid>
      <dc:creator>praprama</dc:creator>
      <dc:date>2010-08-30T04:33:41Z</dc:date>
    </item>
    <item>
      <title>Re: Can the ASA 'sla monitor' log state changes to the log buffe</title>
      <link>https://community.cisco.com/t5/network-security/can-the-asa-sla-monitor-log-state-changes-to-the-log-buffer/m-p/1499491#M658880</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Nagaraja and Prapanch,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am already familiar these links; to be clear, none make mention of non-debug logging, nor any specific sla log commands.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, I can confirm (even on version 8.0) that the Nagaraja's 622001 events do get logged *without debug enabled*.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;Aug 30 2010 14:58:27: %ASA-6-622001: Removing tracked route 0.0.0.0 0.0.0.0 10.1.1.1, distance 1, table Default-IP-Routing-Table, on interface outside&lt;BR /&gt;...&lt;BR /&gt;Aug 30 2010 14:58:27: %ASA-6-622001: Adding tracked route 0.0.0.0 0.0.0.0 10.1.1.1, distance 1, table Default-IP-Routing-Table, on interface outside&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Hence these logs are available without any extra commands (from the original post).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The catch is these log events are type 6, which requires the very verbose:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; logging buffered informational&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So in most production environments these logs will quickly expire when the log wraps, even with a megabyte of local logs:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; logging buffer-size 1048576&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jason&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Aug 2010 05:50:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-the-asa-sla-monitor-log-state-changes-to-the-log-buffer/m-p/1499491#M658880</guid>
      <dc:creator>j.irwin</dc:creator>
      <dc:date>2010-08-30T05:50:59Z</dc:date>
    </item>
    <item>
      <title>Re: Can the ASA 'sla monitor' log state changes to the log buffe</title>
      <link>https://community.cisco.com/t5/network-security/can-the-asa-sla-monitor-log-state-changes-to-the-log-buffer/m-p/1499492#M658881</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just to clarify a thing here. Any message starting with the format of %PIX/ASA-x-yyyyyy is a syslog message and will not require any debugs to be run on the device. The link with the configuration example for SLA monitoring shows all logs produced when the tracking succeeds and when the tracking fails.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regarding the syslog like below:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="content"&gt;&lt;PRE&gt;&lt;STRONG&gt;%PIX-6-622001: Removing tracked route 0.0.0.0 0.0.0.0 10.200.159.1,&amp;nbsp; &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; distance 1, table Default-IP-Routing-Table, on interface &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; outside&lt;BR /&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;If you do not want to enable buffered logging&lt;/SPAN&gt; &lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;at level 6, you can change the default level of this message to something higher using the below command:&lt;BR /&gt;&lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa72/command/reference/l2_72.html#wp1689570"&gt;http://www.cisco.com/en/US/docs/security/asa/asa72/command/reference/l2_72.html#wp1689570&lt;/A&gt;&lt;/SPAN&gt; &lt;BR /&gt;&lt;BR /&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;So for example, if you would like to enable logging at level 3(errors) but still want the syslog id 622001 to be logged, you can change the level of this &lt;BR /&gt;command to &lt;STRONG&gt;errors &lt;/STRONG&gt;using:&lt;BR /&gt;&lt;BR /&gt;&lt;EM&gt;logging message &lt;STRONG&gt;622001&lt;/STRONG&gt; level &lt;STRONG&gt;3&lt;/STRONG&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;BR /&gt;Once this is done, you should see this message being logged at level 3 in the buffer. Hope this helps:&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Prapanch&lt;BR /&gt;&lt;/SPAN&gt;&lt;/PRE&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Aug 2010 06:20:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-the-asa-sla-monitor-log-state-changes-to-the-log-buffer/m-p/1499492#M658881</guid>
      <dc:creator>praprama</dc:creator>
      <dc:date>2010-08-30T06:20:25Z</dc:date>
    </item>
    <item>
      <title>Re: Can the ASA 'sla monitor' log state changes to the log buffe</title>
      <link>https://community.cisco.com/t5/network-security/can-the-asa-sla-monitor-log-state-changes-to-the-log-buffer/m-p/1499493#M658883</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you do not want to log at level 6, you can change the message level.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;logging message 622001 level 3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This command will force the ASA to log 622001 at level 3. You can also&lt;/P&gt;&lt;P&gt;configure SNMP logging or mail logging for this specific event (although&lt;/P&gt;&lt;P&gt;mail logging is not very efficient).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this works for you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NT&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Aug 2010 06:21:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-the-asa-sla-monitor-log-state-changes-to-the-log-buffer/m-p/1499493#M658883</guid>
      <dc:creator>Nagaraja Thanthry</dc:creator>
      <dc:date>2010-08-30T06:21:22Z</dc:date>
    </item>
  </channel>
</rss>

