<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA Email logging issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-email-logging-issue/m-p/1418053#M806733</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I ran the capture and I can see bi-directional communication between the firewall&lt;/P&gt;&lt;P&gt;and the email server. I've attached the some of the capture traffic.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 21 Dec 2009 18:36:02 GMT</pubDate>
    <dc:creator>d3mb0y555</dc:creator>
    <dc:date>2009-12-21T18:36:02Z</dc:date>
    <item>
      <title>ASA Email logging issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-email-logging-issue/m-p/1418044#M806724</link>
      <description>&lt;P&gt;I have an ASA 5520 that I am trying to configure to send email alerts to my exchange account. I have all the proper information and I 've configured what I think to be the necessary parts but I still do not receive emails from the firewall. Any help?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;logging enable&lt;BR /&gt;logging timestamp&lt;BR /&gt;logging standby&lt;BR /&gt;logging list LOGGING level informational&lt;BR /&gt;logging console emergencies&lt;BR /&gt;logging monitor critical&lt;BR /&gt;logging buffered informational&lt;BR /&gt;logging trap critical&lt;BR /&gt;logging history errors&lt;BR /&gt;logging asdm warnings&lt;BR /&gt;logging mail errors&lt;BR /&gt;logging from-address &lt;A href="mailto:x.x.x@x.x.x.x" target="_blank"&gt;x.x.x@x.x.x.x&lt;/A&gt;&lt;BR /&gt;logging recipient-address &lt;A href="mailto:x.x.x@x.x.x.x" target="_blank"&gt;x.x.x@x.x.x.x&lt;/A&gt; level errors&lt;BR /&gt;logging facility 23&lt;BR /&gt;logging queue 1000&lt;BR /&gt;logging host inside CISCOWKS&lt;BR /&gt;logging host inside x.x.x.x&lt;BR /&gt;logging host inside x.x.x.x&lt;BR /&gt;logging host inside x.x.x.x&lt;BR /&gt;logging debug-trace&lt;BR /&gt;no logging message 106015&lt;BR /&gt;no logging message 106011&lt;BR /&gt;no logging message 302015&lt;BR /&gt;no logging message 302014&lt;BR /&gt;no logging message 302013&lt;BR /&gt;no logging message 304001&lt;BR /&gt;no logging message 302016&lt;/P&gt;&lt;P&gt;smtp-server x.x.x.x&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 16:50:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-email-logging-issue/m-p/1418044#M806724</guid>
      <dc:creator>d3mb0y555</dc:creator>
      <dc:date>2019-03-11T16:50:19Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Email logging issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-email-logging-issue/m-p/1418045#M806725</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you getting logs on the syslog servers configured?&lt;/P&gt;&lt;P&gt;Is just the e-mail alert that is not getting to your e-mail account?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If so, are the from &amp;amp; recipient e-mail addresses sending and receiving any e-mail (properly configured)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Dec 2009 22:58:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-email-logging-issue/m-p/1418045#M806725</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2009-12-18T22:58:54Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Email logging issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-email-logging-issue/m-p/1418046#M806726</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The send and receive email addresses are properly configured. The sysl&lt;/P&gt;&lt;P&gt;og server, however, I can not confirm at the moment if it is receiving syslog messages.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But right now my email account is not receiving logs.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 19 Dec 2009 00:59:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-email-logging-issue/m-p/1418046#M806726</guid>
      <dc:creator>d3mb0y555</dc:creator>
      <dc:date>2009-12-19T00:59:49Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Email logging issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-email-logging-issue/m-p/1418047#M806727</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Could you try this pls.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;conf t&lt;/P&gt;&lt;P&gt;loggin message 111008 level 3&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;exit&lt;/P&gt;&lt;P&gt;write mem&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now, see if you receive the message via e-mail. You are only logging error level to mail and there may not be many that are generated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa80/command/reference/l2.html#wp1751895"&gt;http://www.cisco.com/en/US/docs/security/asa/asa80/command/reference/l2.html#wp1751895&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV class="pEx1_Example1"&gt;&lt;PRE&gt;hostname(config)# &lt;SPAN class="cExBold"&gt;logging mail critical&lt;BR /&gt;&lt;/SPAN&gt;&lt;/PRE&gt;&lt;/DIV&gt;&lt;P&gt;&lt;A name="wp1752192"&gt;&lt;/A&gt;&lt;/P&gt;&lt;DIV class="pEx1_Example1"&gt;&lt;PRE&gt;&lt;!--&lt;code class="cExPlain"&gt;--&gt;hostname(config)# &lt;SPAN class="cExBold"&gt;&lt;SPAN&gt;logging from-address &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:ciscosecurityappliance@example.com"&gt;ciscosecurityappliance@example.com&lt;/A&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/PRE&gt;&lt;/DIV&gt;&lt;P&gt;&lt;A name="wp1752196"&gt;&lt;/A&gt;&lt;/P&gt;&lt;DIV class="pEx1_Example1"&gt;&lt;PRE&gt;&lt;!--&lt;code class="cExPlain"&gt;--&gt;hostname(config)# &lt;SPAN class="cExBold"&gt;&lt;SPAN&gt;logging recipient-address &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:admin@example.com"&gt;admin@example.com&lt;/A&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/PRE&gt;&lt;/DIV&gt;&lt;P&gt;&lt;A name="wp1752200"&gt;&lt;/A&gt;&lt;/P&gt;&lt;DIV class="pEx1_Example1"&gt;&lt;PRE&gt;&lt;!--&lt;code class="cExPlain"&gt;--&gt;hostname(config)# &lt;SPAN class="cExBold"&gt;smtp-server pri-smtp-host sec-smtp-host&lt;BR /&gt;&lt;/SPAN&gt;&lt;/PRE&gt;&lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 19 Dec 2009 01:25:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-email-logging-issue/m-p/1418047#M806727</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2009-12-19T01:25:39Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Email logging issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-email-logging-issue/m-p/1418048#M806728</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;KS,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;I tried that but to no avail. Here's the current config now.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;logging enable&lt;BR /&gt;logging timestamp&lt;BR /&gt;logging standby&lt;BR /&gt;logging list LOGGING level informational&lt;BR /&gt;logging console emergencies&lt;BR /&gt;logging monitor critical&lt;BR /&gt;logging buffered informational&lt;BR /&gt;logging trap critical&lt;BR /&gt;logging history errors&lt;BR /&gt;logging asdm warnings&lt;BR /&gt;logging mail critical&lt;BR /&gt;logging from-address &lt;A href="mailto:admin@example.com"&gt;admin@example.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;logging recipient-address &lt;A href="mailto:admin@example.com"&gt;admin@example.com&lt;/A&gt; level informational&lt;BR /&gt;logging recipient-address &lt;A href="mailto:admin@example.com "&gt;admin@example.com&lt;SPAN style="color: #333333;"&gt; &lt;/SPAN&gt;&lt;/A&gt; level errors&lt;BR /&gt;logging recipient-address &lt;A href="mailto:admin@example.com"&gt;admin@example.com&lt;/A&gt; level errors&lt;BR /&gt;logging facility 23&lt;BR /&gt;logging queue 1000&lt;BR /&gt;logging host inside CISCOWKS&lt;BR /&gt;logging host inside x.x.x.x&lt;BR /&gt;logging host inside x.x.x.x&lt;BR /&gt;logging host inside x.x.x.x&lt;BR /&gt;logging debug-trace&lt;BR /&gt;no logging message 106015&lt;BR /&gt;no logging message 106011&lt;BR /&gt;no logging message 302015&lt;BR /&gt;no logging message 302014&lt;BR /&gt;no logging message 302013&lt;BR /&gt;no logging message 304001&lt;BR /&gt;no logging message 302016&lt;BR /&gt;logging message 111008 level errors&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 19 Dec 2009 01:52:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-email-logging-issue/m-p/1418048#M806728</guid>
      <dc:creator>d3mb0y555</dc:creator>
      <dc:date>2009-12-19T01:52:30Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Email logging issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-email-logging-issue/m-p/1418049#M806729</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Now your logging mail shows critical. It showed errors before.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;change it to errors pls.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;conf t&lt;/P&gt;&lt;P&gt;loggin mail errors&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Issue a wri mem and see if it sends you the 111009 syslog via e-mail.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 19 Dec 2009 01:57:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-email-logging-issue/m-p/1418049#M806729</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2009-12-19T01:57:58Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Email logging issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-email-logging-issue/m-p/1418050#M806730</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;KS,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;I just made that change but still no email. Any other suggestions?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Arshad&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 19 Dec 2009 02:26:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-email-logging-issue/m-p/1418050#M806730</guid>
      <dc:creator>d3mb0y555</dc:creator>
      <dc:date>2009-12-19T02:26:32Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Email logging issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-email-logging-issue/m-p/1418051#M806731</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is the e-mail server accessible from the ASA itself?&lt;/P&gt;&lt;P&gt;Are the e-mail getting to the e-mail server and just not getting to your e-mail account?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can try a capture to see if the ASA is sending e-mails to the server:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list 101 permit ip host IP_of_the_ASA host IP_of_the_e-mail_server&lt;BR /&gt;access-list 101 permit ip host IP_of_the_e-mail_server host IP_of_the_ASA&lt;/P&gt;&lt;P&gt;capture E-MAIL access-list 101 packet-length 1512 interface (name_of_the_interface_used_to_reach_the_mail_server)&lt;/P&gt;&lt;P&gt;show capture E-MAIL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This will show us if the ASA is indeed sending packets to the e-mail server, and what kind of packets, and if there's a failure....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 19 Dec 2009 03:27:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-email-logging-issue/m-p/1418051#M806731</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2009-12-19T03:27:00Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Email logging issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-email-logging-issue/m-p/1418052#M806732</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I hope the firewall has connectivity to the e-mail server. Make sure to ping it using its IP address that you configured in the smtp-server line.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Besides that we just have to do captures like Federico says.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are running 7.2.4 and above you can simplify the capture command as following without any ACL.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;cap capin int inside match tcp host 10.10.10.1 any eq 25&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;where 10.10.10.1 is the IP address of the inside interface. I am assuming the e-mail server is on the inside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Dec 2009 13:56:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-email-logging-issue/m-p/1418052#M806732</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2009-12-21T13:56:55Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Email logging issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-email-logging-issue/m-p/1418053#M806733</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I ran the capture and I can see bi-directional communication between the firewall&lt;/P&gt;&lt;P&gt;and the email server. I've attached the some of the capture traffic.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Dec 2009 18:36:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-email-logging-issue/m-p/1418053#M806733</guid>
      <dc:creator>d3mb0y555</dc:creator>
      <dc:date>2009-12-21T18:36:02Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Email logging issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-email-logging-issue/m-p/1418054#M806734</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok. You are correct I do see bi-directional traffic. That rules the firewall out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check the e-mail server logs, even viewer, smtp-server logs and see if shows any indication of receiving rejecting these e-mails.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Wireshark capture on the server to see what it is doing with the packets that it receives.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Dec 2009 18:50:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-email-logging-issue/m-p/1418054#M806734</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2009-12-21T18:50:04Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Email logging issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-email-logging-issue/m-p/1418055#M806735</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;My exchange administrator checked the server and saw the messages being block by the spam filter. He adjusted the filter and now I'm receiving alerts from the ASA. Thanks alot guys for all the help.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Arshad&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Dec 2009 21:04:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-email-logging-issue/m-p/1418055#M806735</guid>
      <dc:creator>d3mb0y555</dc:creator>
      <dc:date>2009-12-21T21:04:32Z</dc:date>
    </item>
  </channel>
</rss>

