02-22-2019 06:45 AM - edited 02-21-2020 08:51 AM
Hi All,
I have deployed Cisco 2100 series ASA with multi context mode and it contains any any rule in some contexts. So I need to take out all the traffic loggs which hitting any any rule.
Any idea of taking loggs for each any any rule. ? I need to remove this rule before it goes live.
-Dil
Solved! Go to Solution.
02-25-2019 12:48 AM
As for as i know that log do current until buffer over flow, that not cover history of the logs.
As per your orginal post you like to log them and analyse them for later use (correct me if my understanding was wrong) ?
02-22-2019 07:01 AM
Have you configured external log server to log these ? if not you will not able to get that information.
if you like to have all the logs, configure syslog server and route the logs to log server.
02-22-2019 07:07 AM
Hi BB,
I have not configured external server yet , and hope to configure.
I just need to taking out traffic loggs which hitting only any any ACLs.
Regards,
Dilk
02-22-2019 09:18 AM
Sure you configure only those to logs to export to syslog server.
02-22-2019 07:52 PM
Hi
My rule number is 56 for Any Any ACL, how can i create a event for getting logs related to this rule only. please send me how it configure.
I need to capture source and destination with ports which hitting to rule number 56 only.
configured a syslog server also
regards,
Dilk
02-23-2019 03:13 AM
logging enable
logging timestamp
logging message 106100
logging trap informational or debug ( depends on your requirememt)
logging host MANAGEMENT 10.10.10.10
!
access-list 56 XXXXXXX any any log
checking logs
show logging message 106100
here is teh guide
make sure you have syslog server running and you have ACL setup on ASA for that syslog host port 514.
02-23-2019 02:18 PM
Disable logging on all access control entries except the permit ip any any ACL. This can be done in ASDM by unchecking the logging enable check box in each ACL or adding the keywords "logging disable" at the end of each access control entry in the CLI.
02-24-2019 07:25 PM
02-25-2019 12:48 AM
As for as i know that log do current until buffer over flow, that not cover history of the logs.
As per your orginal post you like to log them and analyse them for later use (correct me if my understanding was wrong) ?
02-25-2019 12:57 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide