11-05-2011 03:58 AM - edited 03-07-2019 03:14 AM
How should I configure NX7000 to log acl's hits on a remote syslog server.
Thanks
Rosa
Solved! Go to Solution.
11-22-2011 10:21 AM
Hi Rosa,
The output in your post looks like it is from an ASA firewall. Router will never give you such result in log.
Regards,
jerry
11-07-2011 05:10 AM
For example;
deny ip any host 192.168.1.255 log
Can not see dropped packets on syslog
11-07-2011 05:34 AM
Hi,
can you post show logging output.
Regards.
Alain.
11-07-2011 06:30 AM
# sh logging
Logging console: enabled (Severity: critical)
Logging monitor: disabled
Logging linecard: enabled (Severity: notifications)
Logging timestamp: Seconds
Logging loopback : disabled
Logging server: enabled
{147.65.1.96}
server severity: debugging
server facility: local4
server VRF: default
{/dev/pts/8}
server severity: critical
server facility: local7
server VRF:
{/dev/pts/9}
server severity: critical
server facility: local7
server VRF:
Logging logflash: enabled (Severity: notifications)
Logging logfile: enabled
Name - messages: Severity - notifications Size - 4194304
Facility Default Severity Current Session Severity
-------- ---------------- ------------------------
aaa 3 3
acllog 2 2
aclmgr 3 3
auth 0 0
authpriv 3 3
bootvar 5 5
callhome 2 2
capability 2 2
cdp 2 2
cert_enroll 2 2
cfs 3 3
clis 7 7
cmond 2 2
cmpproxy 2 2
confcheck 2 2
copp 2 2
cron 3 3
daemon 3 3
device_test 2 2
dhcp_snoop 2 2
diag_port_lb 2 2
diagclient 2 2
diagmgr 2 2
eltm 2 2
eth_port_channel 5 5
ethpm 5 5
evmc 5 5
evms 2 2
feature-mgr 2 2
fex 5 5
fs-daemon 2 2
ftp 3 3
ifmgr 5 5
igmp_1 5 5
interface-vlan 2 2
ip 3 3
ipqosmgr 4 4
ipv6 3 3
kern 3 3
l2fm 2 2
l2pt 3 3
l3vm 5 5
licmgr 6 6
local0 3 3
local1 3 3
local2 3 3
local3 3 3
local4 3 3
local5 3 3
local6 3 3
local7 3 3
lpr 3 3
m2rib 2 2
m6rib 5 5
mail 3 3
mcm 2 2
mfdm 2 2
module 5 5
monitor 3 3
mrib 5 5
mvsh 2 2
news 3 3
nfm 5 5
ntp 2 2
oc_usd 3 3
otm 3 3
pixm 4 4
platform 5 5
plugin 2 2
port-profile 2 2
radius 3 3
res_mgr 5 5
rpm 5 5
sal 2 2
securityd 3 3
sksd 3 3
smm 4 4
snmpd 2 2
spm 2 2
stp 3 3
syslog 3 3
sysmgr 3 3
tunnel 2 2
u6rib 5 5
ufdm 2 2
urib 5 5
user 3 3
uucp 3 3
vdc_mgr 6 6
vlan_mgr 2 2
vntag_mgr 2 2
vshd 5 5
xbar 5 5
xmlma 3 3
0(emergencies) 1(alerts) 2(critical)
3(errors) 4(warnings) 5(notifications)
6(information) 7(debugging)
11-07-2011 07:01 AM
Hi,
can you post sh run | i logging
Regards.
Alain.
11-07-2011 07:04 AM
# sh run | i logging
logging server 147.65.1.96 7 use-vrf default facility local4
no logging monitor
#
11-22-2011 03:03 AM
I am still not able to see dropped packets on syslog as they were shown on 6509`s logs on cases as shown in acls below:
deny ip any host 192.168.1.255 log
11-22-2011 08:37 AM
Did you put this command in the ACL config?
statistics per-entry
Here is an example:
N7K-1(config-if)# sh run | sec "ip access-list test"
ip access-list test
statistics per-entry
10 permit ip any any
N7K-1# sh ip access-list
IP access list test
statistics per-entry
10 permit ip any any [match=122]
HTH,
jerry
11-22-2011 10:08 AM
I see, but I am asking for more information. I would like to have something like I have had before.
For example:
Nov 22 16:07:13 stokes-servidores %ASA-4-106023: Deny protocol 41 src stokes-outside:192.88.99.1 dst stokes-inside:147.65.105.155 by access-group "inside_access_out" [0xe9dece0c, 0x0]
Nov 22 16:07:13 stokes-servidores %ASA-4-106023: Deny tcp src stokes-outside:80.202.199.225/64794 dst stokes-inside:147.65.105.145/14605 by access-group "inside_access_out" [0xe9dece0c, 0x0]
Nov 22 16:07:13 stokes-servidores %ASA-4-106023: Deny udp src stokes-outside:177.17.172.96/61710 dst stokes-inside:147.65.105.145/14605 by access-group "inside_access_out" [0xe9dece0c, 0x0]
Nov 22 16:07:13 stokes-servidores %ASA-4-106023: Deny udp src stokes-outside:92.13.227.149/39591 dst stokes-inside:147.65.105.145/14605 by access-group "inside_access_out" [0xe9dece0c, 0x0]
11-22-2011 10:21 AM
Hi Rosa,
The output in your post looks like it is from an ASA firewall. Router will never give you such result in log.
Regards,
jerry
11-22-2011 10:40 AM
What a pit ! Those informations are too helpful.
Thanks a lot.
Rosa
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide