11-14-2013 11:29 AM - edited 03-11-2019 08:05 PM
Hello,
I would like to pull a report for the last 24 hours of all external connection attempts to our ASA. I went into Monitoring via the ASMD (7.1) and changed the logging level to "Informational" however I do not see anything coming in it only seems to be showing my internal going out. Could someone please supply me with some information or direction on where I could find documents for this.
Thanks,
Greg
Solved! Go to Solution.
11-14-2013 01:18 PM
The ASA has a logging buffer that by default is short, it is expected that if you are monitoring traffic to or through the ASA you configure a Syslog server since past events are not saved into disk unless specified.
11-14-2013 02:26 PM
Hello Gregory
My recommendation for this is to leverage the UDP Syslog packets to a External device so you can save memory on the ASA for different traffic.
Note: You should consider Netflow as it will provide you granularity and also depending on the vendor software they will build reports, etc on their own with the data send to the collector.
Rate all of the helpful posts!!!
Regards,
Jcarvaja
Follow me on http://laguiadelnetworking.com
11-14-2013 01:18 PM
The ASA has a logging buffer that by default is short, it is expected that if you are monitoring traffic to or through the ASA you configure a Syslog server since past events are not saved into disk unless specified.
11-14-2013 02:26 PM
Hello Gregory
My recommendation for this is to leverage the UDP Syslog packets to a External device so you can save memory on the ASA for different traffic.
Note: You should consider Netflow as it will provide you granularity and also depending on the vendor software they will build reports, etc on their own with the data send to the collector.
Rate all of the helpful posts!!!
Regards,
Jcarvaja
Follow me on http://laguiadelnetworking.com
11-18-2013 08:06 AM
Thanks guys,
I actually did setup a syslog server thinking that was going to be the ticket but wasn't 100% sure. I will take a look at Netflow options down the road.
11-22-2013 09:47 AM
Guys,
I have a Syslog up and running but am finding I'm not really getting the information I was expecting. I was thinking I would see numerous denied attempts to say port 3389, 23, or other well known ports but really I'm pretty much just seeing alot of "Teardown connections", "Built connections", "Access List permitted", and some randle "Deny TCP (no connection). Now I think the Deny TCP (no connection) may be what I'm looking for but I really expected to see quite a bit more of this type of traffic? I figured I'd pick up some port scanning attempts or something maybe it's there and I just am not viewing it correctly or maybe I'm looking in the wrong place? Maybe I'm just expecting more negative then I should be. Any thoughts?
Thanks,
Greg
11-22-2013 10:38 AM
Hello Greg,
So you are not seeing any Deny ACL???
Look for log ID 106023
106023
106023
106023
106023
106023 p
106023 p
Rate all of the helpful posts!!!
Regards,
Jcarvaja
Follow me on http://laguiadelnetworking.com
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide