<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA 5505 Syslog configuration. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5505-syslog-configuration/m-p/1178401#M840690</link>
    <description>&lt;P&gt;syslog configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;unable to getting logs from server.....&lt;/P&gt;&lt;P&gt;I am getting error in ASA5505-FW#sh logging as mentioned below.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;May 29 2009 02:08:19 172.26.8.254 : %ASA-3-710003: TCP access denied by ACL from&lt;/P&gt;&lt;P&gt; 172.26.8.3/1594 to inside:172.26.8.254/23&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 15:37:28 GMT</pubDate>
    <dc:creator>ntmanjunath</dc:creator>
    <dc:date>2019-03-11T15:37:28Z</dc:date>
    <item>
      <title>ASA 5505 Syslog configuration.</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-syslog-configuration/m-p/1178401#M840690</link>
      <description>&lt;P&gt;syslog configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;unable to getting logs from server.....&lt;/P&gt;&lt;P&gt;I am getting error in ASA5505-FW#sh logging as mentioned below.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;May 29 2009 02:08:19 172.26.8.254 : %ASA-3-710003: TCP access denied by ACL from&lt;/P&gt;&lt;P&gt; 172.26.8.3/1594 to inside:172.26.8.254/23&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 15:37:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-syslog-configuration/m-p/1178401#M840690</guid>
      <dc:creator>ntmanjunath</dc:creator>
      <dc:date>2019-03-11T15:37:28Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5505 Syslog configuration.</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-syslog-configuration/m-p/1178402#M840691</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Where are your acl's at on the firewall? Do you have your firewall configured in transparent mode?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 May 2009 12:33:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-syslog-configuration/m-p/1178402#M840691</guid>
      <dc:creator>John Blakley</dc:creator>
      <dc:date>2009-05-29T12:33:57Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5505 Syslog configuration.</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-syslog-configuration/m-p/1178403#M840692</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;May 29 2009 02:08:19 172.26.8.254 : %ASA-3-710003: TCP access denied by ACL from 172.26.8.3/1594 to inside:172.26.8.254/23 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So you are unable to telnet from 172.26.8.3 PC to the ASA's inside interface 172.26.8.254? You do not have the line "telnet 0 0 inside"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need help with that or do you need help with configuring a syslog server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Flow this link for configuring syslog server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/monitor.html#wp1064726" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/monitor.html#wp1064726&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you need assistance to configure the asa for telnet access pls. read here.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/mgaccess.html#wp1054101" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/mgaccess.html#wp1054101&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 30 May 2009 00:01:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-syslog-configuration/m-p/1178403#M840692</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2009-05-30T00:01:53Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5505 Syslog configuration.</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-syslog-configuration/m-p/1178404#M840693</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have done the configuration as per the ulr.The same error is getting. Please check the configuration and confirm anything needs to update.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Vlan1&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 172.26.8.254 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan2&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address 10.97.37.221 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan3&lt;/P&gt;&lt;P&gt; no nameif&lt;/P&gt;&lt;P&gt; no security-level&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;/P&gt;&lt;P&gt; switchport access vlan 2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;clock timezone IST 5 30&lt;/P&gt;&lt;P&gt;dns server-group DefaultDNS&lt;/P&gt;&lt;P&gt; domain-name default.domain.invalid&lt;/P&gt;&lt;P&gt;access-list 100 extended permit tcp any host 10.97.37.229 eq 3389&lt;/P&gt;&lt;P&gt;access-list 100 extended permit icmp any any echo-reply&lt;/P&gt;&lt;P&gt;access-list 100 extended permit tcp any host 10.97.37.229 eq 445&lt;/P&gt;&lt;P&gt;access-list 100 extended permit tcp any host 10.97.37.221 eq telnet&lt;/P&gt;&lt;P&gt;access-list 100 extended permit tcp any host 10.97.37.229 eq ftp&lt;/P&gt;&lt;P&gt;access-list nonat extended permit ip any 192.168.200.0 255.255.255.192&lt;/P&gt;&lt;P&gt;access-list split_tunnel standard permit 172.26.8.0 255.255.255.0&lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging enable&lt;/P&gt;&lt;P&gt;logging timestamp&lt;/P&gt;&lt;P&gt;logging standby&lt;/P&gt;&lt;P&gt;logging console alerts&lt;/P&gt;&lt;P&gt;logging monitor informational&lt;/P&gt;&lt;P&gt;logging buffered errors&lt;/P&gt;&lt;P&gt;logging trap errors&lt;/P&gt;&lt;P&gt;logging history emergencies&lt;/P&gt;&lt;P&gt;logging asdm informational&lt;/P&gt;&lt;P&gt;logging mail alerts&lt;/P&gt;&lt;P&gt;logging device-id ipaddress inside&lt;/P&gt;&lt;P&gt;logging host inside 172.26.8.3&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;ip local pool vpnpool 192.168.200.1-192.168.200.62 mask 255.255.255.192&lt;/P&gt;&lt;P&gt;ip audit attack action&lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P&gt;asdm image disk0:/asdm-524.bin&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list nonat&lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;static (inside,outside) 10.97.37.229 172.26.8.3 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;access-group 100 in interface outside&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 10.97.37.254 1&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;/P&gt;&lt;P&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/P&gt;&lt;P&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;http 0.0.0.0 0.0.0.0 outside&lt;/P&gt;&lt;P&gt;http 0.0.0.0 0.0.0.0 inside&lt;/P&gt;&lt;P&gt;snmp-server host inside 172.26.8.3 community Airtel&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server community Airtel&lt;/P&gt;&lt;P&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;/P&gt;&lt;P&gt;snmp-server enable traps syslog&lt;/P&gt;&lt;P&gt;crypto ipsec transform-set airtel esp-3des esp-sha-hmac&lt;/P&gt;&lt;P&gt;crypto dynamic-map bharti 10 set transform-set airtel&lt;/P&gt;&lt;P&gt;crypto dynamic-map bharti 10 set security-association lifetime seconds 288000&lt;/P&gt;&lt;P&gt;crypto dynamic-map bharti 10 set reverse-route&lt;/P&gt;&lt;P&gt;crypto map bharti 10 ipsec-isakmp dynamic bharti&lt;/P&gt;&lt;P&gt;crypto map bharti interface outside&lt;/P&gt;&lt;P&gt;crypto isakmp enable outside&lt;/P&gt;&lt;P&gt;crypto isakmp policy 1&lt;/P&gt;&lt;P&gt; authentication pre-share&lt;/P&gt;&lt;P&gt; encryption 3des&lt;/P&gt;&lt;P&gt; hash sha&lt;/P&gt;&lt;P&gt; group 2&lt;/P&gt;&lt;P&gt; lifetime 43200&lt;/P&gt;&lt;P&gt;crypto isakmp nat-traversal  20&lt;/P&gt;&lt;P&gt;telnet 172.26.8.0 255.255.255.0 inside&lt;/P&gt;&lt;P&gt;telnet timeout 30&lt;/P&gt;&lt;P&gt;ssh 0.0.0.0 0.0.0.0 outside&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;dhcpd auto_config inside&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ntp server 172.26.8.3&lt;/P&gt;&lt;P&gt;group-policy VPNclient internal&lt;/P&gt;&lt;P&gt;group-policy VPNclient attributes&lt;/P&gt;&lt;P&gt; dns-server value 10.40.10.1&lt;/P&gt;&lt;P&gt; vpn-tunnel-protocol IPSec&lt;/P&gt;&lt;P&gt; split-tunnel-policy tunnelspecified&lt;/P&gt;&lt;P&gt; split-tunnel-network-list value split_tunnel&lt;/P&gt;&lt;P&gt; default-domain value netsol.com&lt;/P&gt;&lt;P&gt;username manju password sa8Cy29xTh/4YFVH encrypted&lt;/P&gt;&lt;P&gt;tunnel-group IPsecVPN type ipsec-ra&lt;/P&gt;&lt;P&gt;tunnel-group IPSecVPN type ipsec-ra&lt;/P&gt;&lt;P&gt;tunnel-group VPNclient type ipsec-ra&lt;/P&gt;&lt;P&gt;tunnel-group VPNclient general-attributes&lt;/P&gt;&lt;P&gt; address-pool vpnpool&lt;/P&gt;&lt;P&gt; default-group-policy VPNclient&lt;/P&gt;&lt;P&gt;tunnel-group VPNclient ipsec-attributes&lt;/P&gt;&lt;P&gt; pre-shared-key *&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt; match default-inspection-traffic&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map type inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt; parameters&lt;/P&gt;&lt;P&gt;  message-length maximum 512&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Jun 2009 05:18:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-syslog-configuration/m-p/1178404#M840693</guid>
      <dc:creator>ntmanjunath</dc:creator>
      <dc:date>2009-06-02T05:18:44Z</dc:date>
    </item>
  </channel>
</rss>

