Solved

How can I log only specific messages in a Cisco ASA 5505?

Posted on 2012-03-29
2
630 Views
Last Modified: 2012-03-30
The client has a site-to-site VPN with a remote location.  The users then RDP into a remote server and complain about sporadic dropped RDP sessions.  I have turned on logging (buffer informational), but I am seeing too much non-relevant traffic.  I would specifically like to only log the following:

1.  Built inbound TCP connection (302013)
2.  Teardown TCP connection (302014)
3.  Deny TCP (no connection) from ( 106015)

It would be great to limit it to 3389 only, but I will take what I can get on this.  I would appreciate any help on possible syntax to limit the logging to these messages.
0
Comment
Question by:Yockos
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 32

Accepted Solution

by:
harbor235 earned 500 total points
ID: 37786663
You can run debug commands for the VPN related events only, but the log will still grab other events. Ideally you want to log these events to a SYSLOG server where there are lots of tools available for parsing logs. Fro instance if you are on a *NIX SYSLOG server than egrep is your friend. There is also SPLUNK(costly), SolarWinds, etc ...and other pay parsing software suites


harbor235 ;}
0
 

Author Comment

by:Yockos
ID: 37788787
I was afraid of that.  I thought about a syslog server, but it might be too much effort at this point.  I will see if I can catch the problem when they report the drop (they are supposed to as soon as it happens).  If this does not work, then I will re-visit setting up a syslog server or using ASDM.

Thanks for the input.
0

Featured Post

Free Tool: Port Scanner

Check which ports are open to the outside world. Helps make sure that your firewall rules are working as intended.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Exchange server is not supported in any cloud-hosted platform (other than Azure with Azure Premium Storage).
For months I had no idea how to 'discover' the IP address of the other end of a link (without asking someone who knows), and it drove me batty. Think about it. You can't use Cisco Discovery Protocol (CDP) because it's not implemented on the ASAs.…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …

726 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question