cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
478
Views
0
Helpful
1
Replies

Firewall access rule log hits

jbaldwin33
Level 1
Level 1

I set up an access rule to deny any any out port 25.  I have some hits and want to know what ip address is hitting the access rule.  How do I set up logging?  Then how do I view the log to see the hits?

1 Reply 1

Hi,

 What FW is it?

You can see logs in ASDM (GUI interface). Access the ASA through the GUI interface (ASDM).

Once you log in to the ASDM, go to

Configuration > firwall > access rules

Right Click on the rule that you had created and choose show log.

 

You will be able to see the ip addresses hitting it. The real time application of the rule.

 

 

For logging.

Install a syslog server and configure the FWs syslog server settings to point to that server.

 

Hope this helps. Let me know if you need more help.

 

Review Cisco Networking for a $25 gift card