<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA5550 - logging disable issue  in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa5550-logging-disable-issue/m-p/1131247#M915142</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As far as I know, you cannot filter syslogs based on particular IPS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 06 Aug 2008 13:40:18 GMT</pubDate>
    <dc:creator>Farrukh Haroon</dc:creator>
    <dc:date>2008-08-06T13:40:18Z</dc:date>
    <item>
      <title>ASA5550 - logging disable issue</title>
      <link>https://community.cisco.com/t5/network-security/asa5550-logging-disable-issue/m-p/1131243#M915125</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My Firewall is an ASA 5550 running software 8.0(3).&lt;/P&gt;&lt;P&gt;I have many times the following message in my logs:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"%asa-2-106006: deny inbound udp from 192.168.1.x/138 to 192.168.1.255/138 on interface outside".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The range 192.168.1.128/25 is the pool for my IPSec remote access users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't want to use the "sysopt connection permit-vpn". So I have some specific rules on my outside interface for VPN access.&lt;/P&gt;&lt;P&gt;I've put 2 rules for disabling logging on Netbios protocol.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"access-list outside_access_in extended deny udp 192.168.1.128 255.255.255.128 host 192.168.1.255 object-group NBT-UDP log disable"&lt;/P&gt;&lt;P&gt;"access-list outside_access_in extended deny udp 192.168.1.128 255.255.255.128 any object-group NBT-UDP log disable"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Object-Group NBT-UDP is defined as below:&lt;/P&gt;&lt;P&gt;object-group service NBT-UDP udp&lt;/P&gt;&lt;P&gt; port-object eq 135&lt;/P&gt;&lt;P&gt; port-object eq 136&lt;/P&gt;&lt;P&gt; port-object eq 137&lt;/P&gt;&lt;P&gt; port-object eq 138&lt;/P&gt;&lt;P&gt; port-object eq 139&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any errors in my config ?&lt;/P&gt;&lt;P&gt;How could I do to remove "noise" provided by NetBios traffic from my IPSec remote users ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Christian&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 13:26:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5550-logging-disable-issue/m-p/1131243#M915125</guid>
      <dc:creator>christian.belkreir</dc:creator>
      <dc:date>2019-03-11T13:26:54Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5550 - logging disable issue</title>
      <link>https://community.cisco.com/t5/network-security/asa5550-logging-disable-issue/m-p/1131244#M915127</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Not all messages are generated due to the 'log' message on the ACL on the ASA/PIX.&lt;/P&gt;&lt;P&gt;As per the command referenace:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;" If you enter the log keyword without any arguments, you enable system log message 106100 at the default level (6) and for the default interval (300 seconds). If you do not enter the log keyword, then the default system log message 106023 is generated. "&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can disable this message by:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no logging message 106006&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But this will disable this message for all flows. You could also push this message to level 7 and log to level 6.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Aug 2008 13:28:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5550-logging-disable-issue/m-p/1131244#M915127</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-08-06T13:28:03Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5550 - logging disable issue</title>
      <link>https://community.cisco.com/t5/network-security/asa5550-logging-disable-issue/m-p/1131245#M915130</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your answer Farrukh.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But I don't want to disable syslog message 106006.&lt;/P&gt;&lt;P&gt;I only want to disable logging for netbios traffic on broadcast address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible or not ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Christian&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Aug 2008 13:36:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5550-logging-disable-issue/m-p/1131245#M915130</guid>
      <dc:creator>christian.belkreir</dc:creator>
      <dc:date>2008-08-06T13:36:21Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5550 - logging disable issue</title>
      <link>https://community.cisco.com/t5/network-security/asa5550-logging-disable-issue/m-p/1131246#M915138</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As far as I know, you cannot filter syslogs based on particular IPS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Aug 2008 13:40:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5550-logging-disable-issue/m-p/1131246#M915138</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-08-06T13:40:16Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5550 - logging disable issue</title>
      <link>https://community.cisco.com/t5/network-security/asa5550-logging-disable-issue/m-p/1131247#M915142</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As far as I know, you cannot filter syslogs based on particular IPS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Aug 2008 13:40:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5550-logging-disable-issue/m-p/1131247#M915142</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-08-06T13:40:18Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5550 - logging disable issue</title>
      <link>https://community.cisco.com/t5/network-security/asa5550-logging-disable-issue/m-p/1131248#M915143</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I agree with you regarding the "logging filter" command.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I well understand your answer, in my case, the log didn't come from the ACL engine.&lt;/P&gt;&lt;P&gt;So putting rules with option "log disable", as I've done, will not solve my issue ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Christian&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Aug 2008 13:47:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5550-logging-disable-issue/m-p/1131248#M915143</guid>
      <dc:creator>christian.belkreir</dc:creator>
      <dc:date>2008-08-06T13:47:31Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5550 - logging disable issue</title>
      <link>https://community.cisco.com/t5/network-security/asa5550-logging-disable-issue/m-p/1131249#M915144</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yup it did not come from the ACL engine, that seems obvious and this is a pretty old behavior of the finesse code. It runs two sets of logging functions. Even if you don't have ANY acl on a interface, all connection messages are 'logged' on the firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Aug 2008 13:55:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5550-logging-disable-issue/m-p/1131249#M915144</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-08-06T13:55:19Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5550 - logging disable issue</title>
      <link>https://community.cisco.com/t5/network-security/asa5550-logging-disable-issue/m-p/1131250#M915148</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK.&lt;/P&gt;&lt;P&gt;Thanks for your help and your explaination.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Christian&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Aug 2008 14:03:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5550-logging-disable-issue/m-p/1131250#M915148</guid>
      <dc:creator>christian.belkreir</dc:creator>
      <dc:date>2008-08-06T14:03:59Z</dc:date>
    </item>
  </channel>
</rss>

