<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic  Hi , use command &amp;quot;logging in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-106100-not-logging-acl-activity/m-p/2557157#M934404</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;use command "logging message 106100"&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;SPAN style="color: rgb(0, 0, 0); font-family: arial, helvetica, sans-serif; font-size: 12px; line-height: normal;"&gt;In this case, issue the&lt;/SPAN&gt;&lt;SPAN style="color:#FF0000;"&gt;&lt;SPAN style="font-size:14px;"&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif; line-height: normal;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;B style="color: rgb(0, 0, 0); font-family: arial, helvetica, sans-serif; font-size: 12px; line-height: normal;"&gt;logging message 106100&lt;/B&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="color:#FFFF00;"&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif; font-size: 12px; line-height: normal;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="color: rgb(0, 0, 0); font-family: arial, helvetica, sans-serif; font-size: 12px; line-height: normal;"&gt;command to enable the message&amp;nbsp;&lt;/SPAN&gt;&lt;TT style="color: rgb(0, 0, 0); font-size: 12px; line-height: normal;"&gt;106100&lt;/TT&gt;&lt;SPAN style="color: rgb(0, 0, 0); font-family: arial, helvetica, sans-serif; font-size: 12px; line-height: normal;"&gt;.&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;SPAN style="color: rgb(0, 0, 0); font-family: arial, helvetica, sans-serif; font-size: 12px; line-height: normal;"&gt;HTH&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;SPAN style="color: rgb(0, 0, 0); font-family: arial, helvetica, sans-serif; font-size: 12px; line-height: normal;"&gt;Sandy&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 10 Jul 2014 10:55:19 GMT</pubDate>
    <dc:creator>SANTHOSHKUMAR SARAVANAN</dc:creator>
    <dc:date>2014-07-10T10:55:19Z</dc:date>
    <item>
      <title>ASA 106100 Not Logging ACL activity</title>
      <link>https://community.cisco.com/t5/network-security/asa-106100-not-logging-acl-activity/m-p/2557156#M934403</link>
      <description>&lt;P&gt;I am attempting to forward logs from my ASA estate to a Skybox server to monitor the useage of the ACL. I have followed all of the relevent steps as defined below but there is no sign of 106100 messages in the either the sent syslog messages, ASDM log or the buffer log.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Enabled syslog;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;logging enable&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Defined the logging levels;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;logging buffered informational&lt;BR /&gt;logging trap informational&lt;BR /&gt;logging asdm informational&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Checked that the message I expect to see is classified as informational and enabled;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;syslog 106100: default-level informational (enabled)&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Checked that the ACL's are being hit by resetting the counters and then checking then are no longer 0&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;The ACL's have logging enabled with the below at the end of each ACL entry;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;log informational interval 300&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The logging rule for the syslog server does report errors\drops which I am not sure why when the other syslog servers don't register issues. The server is pingable from the firewall so it isn't a case of it being unreachable;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Logging to INSIDE x.x.x.x errors: 34&amp;nbsp; dropped: 232&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Show logging output;&lt;/P&gt;&lt;P&gt;Syslog logging: enabled&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Facility: 20&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Timestamp logging: enabled&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Standby logging: disabled&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Debug-trace logging: disabled&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Console logging: disabled&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Monitor logging: disabled&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Buffer logging: level informational, 124277 messages logged&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Trap logging: level informational, facility 20, 124277 messages logged&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Logging to INSIDE x.x.x.x&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Logging to INSIDE x.x.x.x errors: 37&amp;nbsp; dropped: 252&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Permit-hostdown logging: enabled&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; History logging: disabled&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Mail logging: disabled&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ASDM logging: level informational, 124277 messages logged&lt;/P&gt;&lt;P&gt;This is a common problem across three sets of ASA firewalls running different version so it must be something that I am missing.&lt;/P&gt;&lt;P&gt;Any help would be gratefully received.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 13:14:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-106100-not-logging-acl-activity/m-p/2557156#M934403</guid>
      <dc:creator>aaron lyon</dc:creator>
      <dc:date>2020-02-21T13:14:14Z</dc:date>
    </item>
    <item>
      <title> Hi , use command "logging</title>
      <link>https://community.cisco.com/t5/network-security/asa-106100-not-logging-acl-activity/m-p/2557157#M934404</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;use command "logging message 106100"&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;SPAN style="color: rgb(0, 0, 0); font-family: arial, helvetica, sans-serif; font-size: 12px; line-height: normal;"&gt;In this case, issue the&lt;/SPAN&gt;&lt;SPAN style="color:#FF0000;"&gt;&lt;SPAN style="font-size:14px;"&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif; line-height: normal;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;B style="color: rgb(0, 0, 0); font-family: arial, helvetica, sans-serif; font-size: 12px; line-height: normal;"&gt;logging message 106100&lt;/B&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="color:#FFFF00;"&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif; font-size: 12px; line-height: normal;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="color: rgb(0, 0, 0); font-family: arial, helvetica, sans-serif; font-size: 12px; line-height: normal;"&gt;command to enable the message&amp;nbsp;&lt;/SPAN&gt;&lt;TT style="color: rgb(0, 0, 0); font-size: 12px; line-height: normal;"&gt;106100&lt;/TT&gt;&lt;SPAN style="color: rgb(0, 0, 0); font-family: arial, helvetica, sans-serif; font-size: 12px; line-height: normal;"&gt;.&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;SPAN style="color: rgb(0, 0, 0); font-family: arial, helvetica, sans-serif; font-size: 12px; line-height: normal;"&gt;HTH&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;SPAN style="color: rgb(0, 0, 0); font-family: arial, helvetica, sans-serif; font-size: 12px; line-height: normal;"&gt;Sandy&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jul 2014 10:55:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-106100-not-logging-acl-activity/m-p/2557157#M934404</guid>
      <dc:creator>SANTHOSHKUMAR SARAVANAN</dc:creator>
      <dc:date>2014-07-10T10:55:19Z</dc:date>
    </item>
    <item>
      <title>Thank you for the response. I</title>
      <link>https://community.cisco.com/t5/network-security/asa-106100-not-logging-acl-activity/m-p/2557158#M934405</link>
      <description>&lt;P&gt;Thank you for the response. I had checked the show logging message all command and this is already enabled;&lt;/P&gt;&lt;P&gt;syslog 106100: default-level informational (enabled)&lt;/P&gt;&lt;P&gt;I ran the command anyway and it has made no difference and the traffic information is not visible in any of the logs.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jul 2014 11:05:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-106100-not-logging-acl-activity/m-p/2557158#M934405</guid>
      <dc:creator>aaron lyon</dc:creator>
      <dc:date>2014-07-10T11:05:21Z</dc:date>
    </item>
    <item>
      <title>Hi , Have enabled log on your</title>
      <link>https://community.cisco.com/t5/network-security/asa-106100-not-logging-acl-activity/m-p/2557159#M934406</link>
      <description>&lt;P&gt;Hi ,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have enabled log on your ACL command&amp;nbsp;&lt;/P&gt;&lt;P class="pB1_Body1" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; margin: 1px 0em 6px; line-height: normal;"&gt;If you enter the&amp;nbsp;&lt;B class="cBold"&gt;log&lt;/B&gt;&amp;nbsp;option without any arguments, you enable system log message 106100 at the default level (6) and for the default interval (300 seconds). See the following options:&lt;/P&gt;&lt;P&gt;&lt;A name="wp1061701" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 13px; line-height: normal; background-color: rgb(255, 255, 255);"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P class="pBu1_Bullet1" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; margin-right: 0em; margin-bottom: 7px; margin-left: 0.25in; text-indent: -0.25in; line-height: normal;"&gt;•&lt;IMG alt="" border="0" height="2" src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" width="19" /&gt;&lt;EM class="cEmphasis"&gt;level&lt;/EM&gt;—A severity level between 0 and 7. The default is 6.&lt;/P&gt;&lt;P&gt;&lt;A name="wp1061702" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 13px; line-height: normal; background-color: rgb(255, 255, 255);"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P class="pBu1_Bullet1" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; margin-right: 0em; margin-bottom: 7px; margin-left: 0.25in; text-indent: -0.25in; line-height: normal;"&gt;•&lt;IMG alt="" border="0" height="2" src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" width="19" /&gt;&lt;B class="cBold"&gt;interval&amp;nbsp;&lt;/B&gt;&lt;SPAN style="font-style: italic;"&gt;secs&lt;/SPAN&gt;—The time interval in seconds between system messages, from 1 to 600. The default is 300. This value is also used as the timeout value for deleting an inactive flow.&lt;/P&gt;&lt;P&gt;&lt;A name="wp1061703" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 13px; line-height: normal; background-color: rgb(255, 255, 255);"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P class="pBu1_Bullet1" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; margin-right: 0em; margin-bottom: 7px; margin-left: 0.25in; text-indent: -0.25in; line-height: normal;"&gt;•&lt;IMG alt="" border="0" height="2" src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" width="19" /&gt;&lt;B class="cBold"&gt;disable&lt;/B&gt;—Disables all access list logging.&lt;/P&gt;&lt;P&gt;&lt;A name="wp1061704" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 13px; line-height: normal; background-color: rgb(255, 255, 255);"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P class="pBu1_Bullet1" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; margin-right: 0em; margin-bottom: 7px; margin-left: 0.25in; text-indent: -0.25in; line-height: normal;"&gt;•&lt;IMG alt="" border="0" height="2" src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" width="19" /&gt;&lt;B class="cBold"&gt;default&lt;/B&gt;—Enables logging to message 106023. This setting is the same as having no&amp;nbsp;&lt;B class="cBold"&gt;log&lt;/B&gt;&amp;nbsp;option.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;Sandy&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jul 2014 11:36:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-106100-not-logging-acl-activity/m-p/2557159#M934406</guid>
      <dc:creator>SANTHOSHKUMAR SARAVANAN</dc:creator>
      <dc:date>2014-07-10T11:36:21Z</dc:date>
    </item>
    <item>
      <title>Below is a snapshot of one of</title>
      <link>https://community.cisco.com/t5/network-security/asa-106100-not-logging-acl-activity/m-p/2557160#M934407</link>
      <description>&lt;P&gt;Below is a snapshot of one of the access-list lines, so logging is set and was added at the end of each ACL line without any further arguements;&lt;/P&gt;&lt;P&gt;access-list outside_cryptomap_81 line 8 extended permit ip x.x.x.x 255.255.255.0 x.x.x.x 255.255.254.0 log informational interval 300 (hitcnt=408)&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jul 2014 12:27:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-106100-not-logging-acl-activity/m-p/2557160#M934407</guid>
      <dc:creator>aaron lyon</dc:creator>
      <dc:date>2014-07-10T12:27:28Z</dc:date>
    </item>
    <item>
      <title>Can you share me logging</title>
      <link>https://community.cisco.com/t5/network-security/asa-106100-not-logging-acl-activity/m-p/2557161#M934408</link>
      <description>&lt;P&gt;Can you share me logging configuration of your ASA .&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;Sandy&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jul 2014 13:06:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-106100-not-logging-acl-activity/m-p/2557161#M934408</guid>
      <dc:creator>SANTHOSHKUMAR SARAVANAN</dc:creator>
      <dc:date>2014-07-10T13:06:52Z</dc:date>
    </item>
    <item>
      <title>Please see below;logging</title>
      <link>https://community.cisco.com/t5/network-security/asa-106100-not-logging-acl-activity/m-p/2557162#M934409</link>
      <description>&lt;P&gt;Please see below;&lt;/P&gt;&lt;P&gt;logging enable&lt;BR /&gt;logging timestamp&lt;BR /&gt;logging buffer-size 64000&lt;BR /&gt;logging buffered informational&lt;BR /&gt;logging trap notifications&lt;BR /&gt;logging asdm informational&lt;BR /&gt;logging queue 8192&lt;BR /&gt;logging device-id hostname&lt;BR /&gt;logging host inside x.x.x.x&lt;BR /&gt;logging permit-hostdown&lt;BR /&gt;logging rate-limit 30 60 level 7&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jul 2014 13:46:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-106100-not-logging-acl-activity/m-p/2557162#M934409</guid>
      <dc:creator>aaron lyon</dc:creator>
      <dc:date>2014-07-10T13:46:37Z</dc:date>
    </item>
    <item>
      <title>Re: Please see below;logging</title>
      <link>https://community.cisco.com/t5/network-security/asa-106100-not-logging-acl-activity/m-p/3175354#M934410</link>
      <description>I currently have the problem that message(s) 106100 can be sysloged to a server on management interface of a ASA 5525-x. Just stopped working months ago TAC can not figure it out.</description>
      <pubDate>Thu, 24 Aug 2017 15:21:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-106100-not-logging-acl-activity/m-p/3175354#M934410</guid>
      <dc:creator>arnert</dc:creator>
      <dc:date>2017-08-24T15:21:10Z</dc:date>
    </item>
    <item>
      <title>Re: Please see below;logging</title>
      <link>https://community.cisco.com/t5/network-security/asa-106100-not-logging-acl-activity/m-p/3754008#M934411</link>
      <description>&lt;P&gt;Did you ever figure this out?&amp;nbsp; I'm trying to get all of my acls to log permits using 106100 but I cannot get it to work.&amp;nbsp; I guess I could redo all the acls to include "log 6" or something but I would rather not.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Nov 2018 01:52:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-106100-not-logging-acl-activity/m-p/3754008#M934411</guid>
      <dc:creator>cshannahan</dc:creator>
      <dc:date>2018-11-28T01:52:25Z</dc:date>
    </item>
  </channel>
</rss>

