10-11-2017 11:53 PM - edited 02-21-2020 06:28 AM
HI
I have a situation where it seems some error appeared on the fw and deleted rules.
They are not sure what logs they have right now.
In any case what logging levels can track this and how can I go ahead troubleshooting?
In this case config debug is recommended, can someone give me a way forward to work with it as I am not very familiar with ASAs.
Solved! Go to Solution.
10-12-2017 01:40 AM
ASA logging options include local console, local buffer, ASDM buffer, SNMP trap and remote syslog targets. If none of them are enabled then you cannot see any details from the ASA device.
To check the configured logging options, use the following command:
show run logging
10-12-2017 01:26 AM
Bet practice is to use external authentication to a AAA server like ACS or ISE. Then the AAA server logs show you who logged in and when.
You should also setup configuration management using something like RANCID (free tool) or SolarWinds NCM or Cisco Prime Infrastructure (licensed products). With those you have external copies of the previous configuration and can always revert to it.
10-12-2017 01:28 AM
Thanks for the reply.
But lets say now that no logging is enabled can I see any details from the cisco ASA device?
Also how can I check what logging options have been configured on the firewall?
10-12-2017 01:40 AM
ASA logging options include local console, local buffer, ASDM buffer, SNMP trap and remote syslog targets. If none of them are enabled then you cannot see any details from the ASA device.
To check the configured logging options, use the following command:
show run logging
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide