cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
466
Views
0
Helpful
2
Replies

Downloadable ACL with logging?

jcrussell
Level 3
Level 3

I have gotten downloadable ACLs for VPN clients to work just fine with my Cisco ACS server and ASA 8.0(x) code. The problem is logging the information. I want to log certain things over the VPN connection. For example, if a user tries to access a certain IP, I want to block it and log it. The blocking works fine, but no matter what I set the logging level to, I never see the blocked traffic in the server logs. Can anyone point to some documentation or "gotchas" that might help? Thanks!

2 Replies 2

eddie.mitchell
Level 3
Level 3

Can't you just block and log the specific VPN traffic via interface ACL's applied on the ASA?

I need to allow different groups access to different servers. That was the reason for doing downloadable ACLs. I was applying an ACL based on the group mapping set in the ACS server.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: