02-16-2009 05:33 PM
I have gotten downloadable ACLs for VPN clients to work just fine with my Cisco ACS server and ASA 8.0(x) code. The problem is logging the information. I want to log certain things over the VPN connection. For example, if a user tries to access a certain IP, I want to block it and log it. The blocking works fine, but no matter what I set the logging level to, I never see the blocked traffic in the server logs. Can anyone point to some documentation or "gotchas" that might help? Thanks!
02-16-2009 06:54 PM
Can't you just block and log the specific VPN traffic via interface ACL's applied on the ASA?
02-16-2009 07:03 PM
I need to allow different groups access to different servers. That was the reason for doing downloadable ACLs. I was applying an ACL based on the group mapping set in the ACS server.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide