<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA, tracking, failover, *notification* in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-tracking-failover-notification/m-p/1439588#M668590</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can setup syslog and also send email when that particular syslog messages are getting triggered.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The syslog message ID for changes in the tracking is 622001:&lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa80/system/message/logmsgs.html#wp4774896"&gt;http://www.cisco.com/en/US/docs/security/asa/asa80/system/message/logmsgs.html#wp4774896&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Example:&lt;/P&gt;&lt;P&gt;logging list track-list message 622001&lt;/P&gt;&lt;P&gt;logging mail track-list&lt;/P&gt;&lt;P&gt;logging from-address &lt;FROM-EMAIL-ADDRESS&gt;&lt;/FROM-EMAIL-ADDRESS&gt;&lt;/P&gt;&lt;P&gt;logging recipient-address &lt;RECIPIENT-EMAIL-ADDRESS&gt;&lt;/RECIPIENT-EMAIL-ADDRESS&gt;&lt;/P&gt;&lt;P&gt;smtp-server &lt;EMAIL-SERVER&gt;&lt;/EMAIL-SERVER&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;OR/ alternatively you can just send it to a syslog server (kiwi):&lt;/P&gt;&lt;P&gt;logging list track-list message 622001&lt;/P&gt;&lt;P&gt;logging trap track-list&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 17 Jun 2010 16:13:48 GMT</pubDate>
    <dc:creator>Jennifer Halim</dc:creator>
    <dc:date>2010-06-17T16:13:48Z</dc:date>
    <item>
      <title>ASA, tracking, failover, *notification*</title>
      <link>https://community.cisco.com/t5/network-security/asa-tracking-failover-notification/m-p/1439587#M668589</link>
      <description>&lt;P&gt;This was my original thread which is now working great (thanks!):&amp;nbsp; &lt;A class="active_link" href="https://community.cisco.com/thread/2024835?tstart=0" target="_blank"&gt;https://supportforums.cisco.com/thread/2024835?tstart=0&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I notice that when the main line goes down and the backup kicks in, it is transparent to the user, which is great.&amp;nbsp; But one drawback is that I would never know (or delayed to know) when the main line went down.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a way to setup SMTP notifications for this?&amp;nbsp; I'm assuming some SMTP configuration and a syslog server (like Kiwi)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any tips appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 18:00:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-tracking-failover-notification/m-p/1439587#M668589</guid>
      <dc:creator>scott.bridges</dc:creator>
      <dc:date>2019-03-11T18:00:47Z</dc:date>
    </item>
    <item>
      <title>Re: ASA, tracking, failover, *notification*</title>
      <link>https://community.cisco.com/t5/network-security/asa-tracking-failover-notification/m-p/1439588#M668590</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can setup syslog and also send email when that particular syslog messages are getting triggered.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The syslog message ID for changes in the tracking is 622001:&lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa80/system/message/logmsgs.html#wp4774896"&gt;http://www.cisco.com/en/US/docs/security/asa/asa80/system/message/logmsgs.html#wp4774896&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Example:&lt;/P&gt;&lt;P&gt;logging list track-list message 622001&lt;/P&gt;&lt;P&gt;logging mail track-list&lt;/P&gt;&lt;P&gt;logging from-address &lt;FROM-EMAIL-ADDRESS&gt;&lt;/FROM-EMAIL-ADDRESS&gt;&lt;/P&gt;&lt;P&gt;logging recipient-address &lt;RECIPIENT-EMAIL-ADDRESS&gt;&lt;/RECIPIENT-EMAIL-ADDRESS&gt;&lt;/P&gt;&lt;P&gt;smtp-server &lt;EMAIL-SERVER&gt;&lt;/EMAIL-SERVER&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;OR/ alternatively you can just send it to a syslog server (kiwi):&lt;/P&gt;&lt;P&gt;logging list track-list message 622001&lt;/P&gt;&lt;P&gt;logging trap track-list&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Jun 2010 16:13:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-tracking-failover-notification/m-p/1439588#M668590</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-06-17T16:13:48Z</dc:date>
    </item>
    <item>
      <title>Re: ASA, tracking, failover, *notification*</title>
      <link>https://community.cisco.com/t5/network-security/asa-tracking-failover-notification/m-p/1439589#M668591</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for your help and sorry for the delay.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm going with the first suggestion.&amp;nbsp; Here is my config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;logging list track-list message 622001&lt;/P&gt;&lt;P&gt;logging list test message 111001&lt;/P&gt;&lt;P&gt;logging asdm informational&lt;/P&gt;&lt;P&gt;logging mail test&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;logging from-address &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:firewall@company.com"&gt;firewall@company.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;logging recipient-address &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:scott@company.com"&gt;scott@company.com&lt;/A&gt;&lt;SPAN&gt; level errors&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;smtp-server 192.168.1.10&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;I initially created the "track-list" config, but did not receive an email when I unplugged the T1 (activating the failover).&amp;nbsp; I then created the "test" list and assigned it to "111001".&amp;nbsp; From what I read, this should send off an email whenever anything does a "write" command (write mem).&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;I am still not getting an email.&amp;nbsp; Before I start troubleshooting with the SMTP server, is there any way I can make sure the ASA is generating the email?&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;Thank you!&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Jul 2010 19:21:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-tracking-failover-notification/m-p/1439589#M668591</guid>
      <dc:creator>scott.bridges</dc:creator>
      <dc:date>2010-07-01T19:21:46Z</dc:date>
    </item>
    <item>
      <title>Re: ASA, tracking, failover, *notification*</title>
      <link>https://community.cisco.com/t5/network-security/asa-tracking-failover-notification/m-p/1439590#M668592</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As per this line of configuration:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;logging recipient-address &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:scott@company.com"&gt;scott@company.com&lt;/A&gt;&lt;SPAN&gt; level errors&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;--&amp;gt; you'll be sending syslog with errors level (level 3) only, while the test list that you have configured for, ie: syslog# 11101 falls under notification level (level 5).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, please double check if logging has been turned on (show log), otherwise, the command to turn logging on is "logging enable".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To test the syslog mail, i would suggest a few things:&lt;/P&gt;&lt;P&gt;1) Change "logging mail test" to "logging mail 5", and also remove the "level errors" from the logging recipient-address command.&lt;/P&gt;&lt;P&gt;This will prove if you are getting any mails at all from the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) If the above still does not give you any mails, you might want to run packet capture on the ASA interface where the mail server is connected to, to see if the ASA is even sending the email out. If it does, you might want to check your email server. If it doesn't, we might need to troubleshoot more on the syslog email portion.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3) If the above 1) works just fine, then you can tailor the syslog list accordingly.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Jul 2010 23:23:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-tracking-failover-notification/m-p/1439590#M668592</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-07-01T23:23:59Z</dc:date>
    </item>
  </channel>
</rss>

