Downloadable ACL with logging?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-16-2009 05:33 PM
I have gotten downloadable ACLs for VPN clients to work just fine with my Cisco ACS server and ASA 8.0(x) code. The problem is logging the information. I want to log certain things over the VPN connection. For example, if a user tries to access a certain IP, I want to block it and log it. The blocking works fine, but no matter what I set the logging level to, I never see the blocked traffic in the server logs. Can anyone point to some documentation or "gotchas" that might help? Thanks!
- Labels:
-
VPN
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-16-2009 06:54 PM
Can't you just block and log the specific VPN traffic via interface ACL's applied on the ASA?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-16-2009 07:03 PM
I need to allow different groups access to different servers. That was the reason for doing downloadable ACLs. I was applying an ACL based on the group mapping set in the ACS server.
