Solved

Configuring ASA5510 to send logs to Kiwi syslog server

Posted on 2014-02-19
6
3,005 Views
Last Modified: 2014-02-19
I am trying to send logs to my Kiwi Syslog server, but I must be doing something wrong.  If you look a the "show logging" output,  I am getting asdm logs, but no logs sent to my Kiwi server.  

ASA5510# show logging
Syslog logging: enabled
    Facility: 20
    Timestamp logging: enabled
    Standby logging: disabled
    Debug-trace logging: disabled
    Console logging: disabled
    Monitor logging: disabled
    Buffer logging: disabled
    Trap logging: level errors, facility 20, 0 messages logged
        Logging to inside 172.31.252.63
    History logging: disabled
    Device ID: disabled
    Mail logging: disabled
    ASDM logging: level informational, 36911019 messages logged

Any ideas?
0
Comment
Question by:denver218
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
6 Comments
 
LVL 18

Expert Comment

by:Akinsd
ID: 39870312
Is 172.31.252.63 your KIWI server?

Show run logging
0
 
LVL 4

Author Comment

by:denver218
ID: 39870343
Yes it is my kiwi server and i can ping it from the ASA.

ASA5510# show run logging
logging enable
logging timestamp
logging trap errors
logging asdm informational
logging host inside 172.31.252.63
logging permit-hostdown
no logging message 106015
no logging message 313001
no logging message 313008
no logging message 106023
no logging message 710003
no logging message 106100
no logging message 302015
no logging message 302014
no logging message 302013
no logging message 302018
no logging message 302017
no logging message 302016
no logging message 302021
no logging message 302020
0
 
LVL 9

Accepted Solution

by:
ffleisma earned 250 total points
ID: 39870345
first check if logging server is reachable via ping 172.31.252.63

check if you are using the same UDP port 514 (although this is default) for the logging server and the ASA

another thing, which particular logs are you looking for on the syslog server? you might want to adjust the settings on the ACL you are trying to monitor and match it with the trap setting. i can see the trap logging is set to level errors. either adjust the logging level on the ACL or the trap level.

access-list inside_access_in line 1 extended permit ip any any log 3 interval 300
logging
hope this helps and let us know if you have any further questions
0
Create the perfect environment for any meeting

You might have a modern environment with all sorts of high-tech equipment, but what makes it worthwhile is how you seamlessly bring together the presentation with audio, video and lighting. The ATEN Control System provides integrated control and system automation.

 
LVL 18

Assisted Solution

by:Akinsd
Akinsd earned 250 total points
ID: 39870373
packet-tracer input inside udp ip.of.asa 514 172.31.252.63 514 de

Focus more on phase 2 (ACL).
That should tell if the ASA is filtering the packet
0
 
LVL 4

Author Closing Comment

by:denver218
ID: 39871230
Thanks guys, it works now.  I didn't change anything, but when I came back from lunch I saw logs from the ASA in the Kiwi server.  Its been sending logs since.  Thanks.
0
 
LVL 18

Expert Comment

by:Akinsd
ID: 39872073
Excellent!
0

Featured Post

Free Tool: ZipGrep

ZipGrep is a utility that can list and search zip (.war, .ear, .jar, etc) archives for text patterns, without the need to extract the archive's contents.

One of a set of tools we're offering as a way to say thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
ACL deny / Permit 10 56
Port forwarding on ubuntu 8 46
how to know if a router is connected to a certain port 9 49
Programmable Firewall Router? 3 25
In the hope of saving someone else's sanity... About a year ago we bought a Cisco 1921 router with two ADSL/VDSL EHWIC cards to load balance local network traffic over the two broadband lines we have, but we couldn't get the routing to work consi…
When speed and performance are vital to revenue, companies must have complete confidence in their cloud environment.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …

710 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question