cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
774
Views
0
Helpful
1
Replies

delayed log from pix to syslog server.

1978gamayun
Level 1
Level 1
I have pix 515E 7.0 (4). For some time logging on to the server is delayed. Do not come all the logs. The configuration has not changed. In what may be the problem?

Time on both devices the same.

Oct 13 11:26:19 62.*.*.81 Oct 13 2011 11:05:40: %PIX-4-106023: Deny icmp src outside_mss:62.177.32.110 dst dmz2:62.*.*.177 (type 3, code 1) by access-group "ACL_OUTSIDE_MSS_IN"

Oct 13 11:26:27 62.*.*.81 Oct 13 2011 11:05:48: %PIX-4-106023: Deny tcp src outside_mss:114.228.112.60/4496 dst dmz2:62.*.*.186/8080 by access-group "ACL_OUTSIDE_MSS_IN"

Oct 13 11:26:35 62.*.*.81 Oct 13 2011 11:05:56: %PIX-4-106023: Deny icmp src outside_mss:62.177.32.110 dst dmz2:62.*.*.177 (type 3, code 1) by access-group "ACL_OUTSIDE_MSS_IN"

After reloading syslog server time is ok.

Oct 13 11:26:43 62.*.*.81 Oct 13 2011 11:26:39: %PIX-4-106023: Deny udp src outside_mss:95.81.43.112/35691 dst transit:72.*.*.169/28636 by access-group "ACL_OUTSIDE_MSS_IN"

Oct 13 11:26:51 62.*.*.81 Oct 13 2011 11:26:39: %PIX-4-106023: Deny icmp src outside_mss:92.126.103.190 dst transit:72.*.*.169 (type 3, code 3) by access-group "ACL_OUTSIDE_MSS_IN"

Oct 13 11:27:07 62.*.*.81 Oct 13 2011 11:26:40: %PIX-4-106023: Deny icmp src outside_mss:62.177.32.110 dst dmz2:62.*.*.177 (type 3, code 1) by access-group "ACL_OUTSIDE_MSS_IN"

but after few times:

Oct 13 11:30:11 62.*.*.81 Oct 13 2011 11:26:52: %PIX-4-106023: Deny icmp src outside_mss:89.222.200.250 dst transit:72.*.*.169 (type 11, code 0) by access-group "ACL_OUTSIDE_MSS_IN"

Oct 13 11:30:20 62.*.*.81 Oct 13 2011 11:26:53: %PIX-4-106023: Deny tcp src outside_mss:116.23.30.193/43254 dst dmz2:62.*.*.186/8080 by access-group "ACL_OUTSIDE_MSS_IN"

Oct 13 11:30:28 62.*.*.81 Oct 13 2011 11:26:53: %PIX-4-106023: Deny icmp src outside_mss:178.219.192.2 dst transit:72.*.*.169 (type 3, code 3) by access-group "ACL_OUTSIDE_MSS_IN"

1 Reply 1

mirober2
Cisco Employee
Cisco Employee

Hello,

First you'll need to narrow down if the PIX is not sending logs during the time gaps or if they are not being displayed by your syslog server. You can use packet captures on the PIX and Wireshark on the server to capture all UDP/514 traffic and identify where the syslogs are getting lost. This guide explains how to setup captures on the PIX:

https://supportforums.cisco.com/docs/DOC-17345

Hope that helps.

-Mike

Review Cisco Networking for a $25 gift card