01-22-2012 08:34 PM - edited 03-11-2019 03:17 PM
Hi,
I've configured following the ASA:
pager lines 24
logging enable
logging timestamp
logging buffer-size 512000
logging asdm-buffer-size 512
logging monitor informational
logging buffered informational
logging trap debugging
logging asdm informational
logging debug-trace
no logging message 106015
no logging message 313001
no logging message 313008
no logging message 106023
no logging message 710003
no logging message 106100
no logging message 302015
no logging message 302014
no logging message 302013
no logging message 302018
no logging message 302017
no logging message 302016
no logging message 302021
no logging message 302020
flow-export destination INSIDE 10.1.10.43 9996
flow-export template timeout-rate 1
access-list DMZ_NW extended permit tcp host 1.1.1.1 host 1.1.1.1 eq 1 log
access-list DMZ_NW extended permit udp host 1.1.1.1 host 1.1.1.1 eq 1 log
access-list DMZ_NW extended permit icmp host 1.1.1.1 host 1.1.1.1 echo log
access-list DMZ_NW extended permit ip any 12.26.0.0 255.255.0.0 log
access-list DMZ_NW extended permit ip any 17.14.0.0 255.255.0.0 log
access-list DMZ_NW extended permit ip any 15.28.0.0 255.255.0.0 log
access-list DMZ_NW extended permit ip any any
access-group DMZ_NW in interface DMZ
as per above ACL, I want to log all traffice to those subnets but the syslog server isn't showing that longging information. it only shows generic messeges of local.debug.
could you advise please how do I send all logging of all "log" to the syslog server?
Thank you.
01-22-2012 08:47 PM
Hello Gavin,
Please add:
logging host inside 10.1.10.43 ( If that is the syslog server)
Regards,
Julio
01-24-2012 09:02 PM
HI,
I made the chage so I see a little more detail now (i.e. i see only source IP address in logging, I don't see destination IP address in the logging). how do I configure it so that it will show source, destination IP and source & destination port.
Thanks...
01-24-2012 10:08 PM
Hello,
Please add - logging facility 23 command.
I mean you already have the debugging level for the server.
What kind of syslog server are you using?
01-24-2012 10:44 PM
Hi Julio, Thanks for your reply. I just entered that command you recommended. I'm using "kiwi" syslog server. which one is recommended?
Thanks again,
Gavin.
01-25-2012 10:26 AM
Hello Gavin,
the Kiwi syslog is fine, are you getting the debuggin level messages (7), I mean you are logging everything you should see what you are looking for.
Regards,
Julio
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide