cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
306
Views
0
Helpful
1
Replies

View threat defense service policy log

alireza82
Level 1
Level 1

Hi everyone

I just config threat defense service policy in ftd 7.2.4, the problem is when the connection limit arrise

I can't find traffic drop log. policy work's fine and drop traffic at limit I expect, but i can't find any corresponding log in fmc.

Any suggestions? 

1 Reply 1

JennieZhang
Cisco Employee
Cisco Employee

Hello @alireza82 

As per my understanding, the issue is that you can not find any events from  "events" under "Connections" from  "analysis" menu, although the connection was disconnected. is this understanding correct?

If yes, how is the logging options configured in your FMC?

https://www.cisco.com/c/en/us/td/docs/security/firepower/70/configuration/guide/fpmc-config-guide-v70/connection_logging.html?bookSearch=true#ID-2174-0000034c

Please kindly check above page to make sure that you have configured appropriate logging options for your ACP rules.

If my above understanding is incorrect please let me know the details, such as how you configured logging options, how you tested and confirmed that the connection was disconnected. 

Regards

 

 

Review Cisco Networking for a $25 gift card