cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
623
Views
0
Helpful
3
Replies

view what happen to my network?

superlubis
Level 1
Level 1

I have asa as a gateway to internet, can i have a complete view or log traffic flow through my asa, i already try netflow but what i see is top-n traffic not all traffic.

Thx

3 Replies 3

You can use syslog to send all the connection-logs to an internal server (I would use a linux-box with syslog-ng). There you have all sessions that were used through the ASA. On the server you can search or filter these logs with your native tools (grep, tail, etc.). If you need more comfort there are several commercial solutions available.

logging enable

logging timestamp

logging trap informational

logging device-id hostname

logging host inside YOUR-LOG-HOST-IP

-- 
Don't stop after you've improved your network! Improve the world by lending money to the working poor:
http://www.kiva.org/invitedby/karsteni

That will send all informational level log, can i just send ip src and port and dest ip port for traffic analysis?

Thx

That will be a little bit tricky. You can disable specific messages or change the severity-level of the logging to fit your needs. But the easiest will probably be to filter the messages on your syslog-server.

-- 
Don't stop after you've improved your network! Improve the world by lending money to the working poor:
http://www.kiva.org/invitedby/karsteni

Review Cisco Networking for a $25 gift card