<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Unable to log http requests in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/unable-to-log-http-requests/m-p/1298825#M802287</link>
    <description>&lt;P&gt;All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've got a situation where I need to log http requests from a couple of systems. I also have regex class-maps that I match on to restrict only certain users from getting on the web.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The default inspection is applied as a global policy, and my regex policy (INBOUND) is applied to the inside interface. I don't get hits on the inspect for this class map:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map REPORT&lt;/P&gt;&lt;P&gt; match access-list MONITOR&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list MONITOR; 2 elements&lt;/P&gt;&lt;P&gt;access-list MONITOR line 1 extended permit ip host 10.5.5.5 any (hitcnt=0) 0x0c07d07d&lt;/P&gt;&lt;P&gt;access-list MONITOR line 2 extended permit ip host 10.5.5.50 any (hitcnt=0) 0x40f63d6c&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map INSIDE&lt;/P&gt;&lt;P&gt;&lt;I&gt; class restricted is my "deny" only certain users portion (not shown above)&lt;/I&gt;&lt;/P&gt;&lt;P&gt; class RESTRICTED&lt;/P&gt;&lt;P&gt;  inspect http RESTRICTED_INTERNET&lt;/P&gt;&lt;P&gt; class REPORT&lt;/P&gt;&lt;P&gt;  inspect http&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I removed the service policy from the interface and reapplied it, but when I did a "sho service-policy inspect http", I don't have any hits on this at all. This DOES work on a 5505, but this is a 5550 and I'm wondering if I'm missing something. I also removed the inspects from the default inspection to see if that was stopping it, but it didn't help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm seeing hits come into the ASA from the outside in that's requesting resources on the inside network, but the only thing that I'm logging from the inside out is the regex policy map denies.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 16:11:23 GMT</pubDate>
    <dc:creator>John Blakley</dc:creator>
    <dc:date>2019-03-11T16:11:23Z</dc:date>
    <item>
      <title>Unable to log http requests</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-log-http-requests/m-p/1298825#M802287</link>
      <description>&lt;P&gt;All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've got a situation where I need to log http requests from a couple of systems. I also have regex class-maps that I match on to restrict only certain users from getting on the web.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The default inspection is applied as a global policy, and my regex policy (INBOUND) is applied to the inside interface. I don't get hits on the inspect for this class map:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map REPORT&lt;/P&gt;&lt;P&gt; match access-list MONITOR&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list MONITOR; 2 elements&lt;/P&gt;&lt;P&gt;access-list MONITOR line 1 extended permit ip host 10.5.5.5 any (hitcnt=0) 0x0c07d07d&lt;/P&gt;&lt;P&gt;access-list MONITOR line 2 extended permit ip host 10.5.5.50 any (hitcnt=0) 0x40f63d6c&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map INSIDE&lt;/P&gt;&lt;P&gt;&lt;I&gt; class restricted is my "deny" only certain users portion (not shown above)&lt;/I&gt;&lt;/P&gt;&lt;P&gt; class RESTRICTED&lt;/P&gt;&lt;P&gt;  inspect http RESTRICTED_INTERNET&lt;/P&gt;&lt;P&gt; class REPORT&lt;/P&gt;&lt;P&gt;  inspect http&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I removed the service policy from the interface and reapplied it, but when I did a "sho service-policy inspect http", I don't have any hits on this at all. This DOES work on a 5505, but this is a 5550 and I'm wondering if I'm missing something. I also removed the inspects from the default inspection to see if that was stopping it, but it didn't help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm seeing hits come into the ASA from the outside in that's requesting resources on the inside network, but the only thing that I'm logging from the inside out is the regex policy map denies.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 16:11:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-log-http-requests/m-p/1298825#M802287</guid>
      <dc:creator>John Blakley</dc:creator>
      <dc:date>2019-03-11T16:11:23Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to log http requests</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-log-http-requests/m-p/1298826#M802288</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Not sure why it does not work on 5550 but you might try this:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/inspect.html#wp1431359" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/inspect.html#wp1431359&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Sep 2009 16:01:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-log-http-requests/m-p/1298826#M802288</guid>
      <dc:creator>Yudong Wu</dc:creator>
      <dc:date>2009-09-01T16:01:40Z</dc:date>
    </item>
  </channel>
</rss>

