I have 5 Zone base firewalls running on 2921 routers. The ire walls work finer, the logging leaves a lot to be desired. Each policy has the default class set to drop log, but the logging is not consistent. Some policies appear to get most, if not all of the dropped pockets while other policies log very little. I had a TAC case earlier but old not get an answer. The logs are definitely missing, I found several instances were a liens could not access something with no packets logged as dropped, but when I added another acl to the class the access was allowed. Are ther logging parameters I need to set to get all the logs? This I a problem as I cannot track problems when the logs are not dependable
Sent from Cisco Technical Support iPad App