logging pix

Posted on 2005-05-17
Last Modified: 2013-11-16

I have turned on logging to my logging server from my pix 515.

I have tried: logging trap debugging which produces a lot records.

This is what I want to log:

access-list inside line 1 deny tcp any any eq 445 (hitcnt=136255)

I have blocked port 445 on my inside interface and now I would like to find out which inside host the traffic is coming from.

I need to filter the logging to only show "deny tcp any any eq 445" Is this possible?

thanks for any help.
Question by:Donnie4572
    LVL 13

    Accepted Solution

    If you append the keyword "log" to the end of your access-list entry, then it should generate log entries at the info level (6) which means you won't need to send traps for the debug level (7) and get all the rest of the stuff. Alternatively, you can specify an even higher level for the log entries to be created at, cutting down on even more of the unwanted entries.

    LVL 12

    Author Comment

    Thanks td_miles!

    I did this:
          access-list inside line 1 deny tcp any any eq 445 log 0

    It is working great.


    Write Comment

    Please enter a first name

    Please enter a last name

    We will never share this with anyone.

    Featured Post

    How your wiki can always stay up-to-date

    Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
    - Increase transparency
    - Onboard new hires faster
    - Access from mobile/offline

    This article assumes you have at least one Cisco ASA or PIX configured with working internet and a non-dynamic, public, address on the outside interface. If you need instructions on how to enable your device for internet, or basic configuration info…
    Do you have a windows based Checkpoint SmartCenter for centralized Checkpoint management?  Have you ever backed up the firewall policy residing on the SmartCenter?  If you have then you know the hassles of connecting to the server, doing an upgrade_…
    Hi everyone! This is Experts Exchange customer support.  This quick video will show you how to change your primary email address.  If you have any questions, then please Write a Comment below!
    Here's a very brief overview of the methods PRTG Network Monitor ( offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…

    779 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    12 Experts available now in Live!

    Get 1:1 Help Now