cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
8776
Views
5
Helpful
15
Replies

FTD ACL Syslog messages

iwearing
Level 1
Level 1

Hi,

Versions FMC V6.2.2, FTD 2120 V8.2.2

I have configured Logging to a syslog server on my ACP Default action. The aim is to Log acl deny messages.

From the cli on the FTD 2120 device I can see hits on the acl.

However my Syslog Server does not receive them. They are visible via FMC event Logs.

Syslog has been defined in Policies - Actions - Alerts with Facility = Local4 and Severity = Warning.

My Syslog Server has also been configured in my Device Platform settings Policy.

I also enabled Syslog logging on another acl rule which has valid permit hit count. These do not appear in my Syslog server.

 

The syslog server is reachable via pings form my FTD device.

Any suggestions to resolve this issue would be appreciated.

 

thanks

Ian

 

 

 

 

 

 

15 Replies 15

Did you find a solution ? 

Review Cisco Networking for a $25 gift card