Solved

Configuring ASA5510 to send logs to Kiwi syslog server

Posted on 2014-02-19
6
2,871 Views
Last Modified: 2014-02-19
I am trying to send logs to my Kiwi Syslog server, but I must be doing something wrong.  If you look a the "show logging" output,  I am getting asdm logs, but no logs sent to my Kiwi server.  

ASA5510# show logging
Syslog logging: enabled
    Facility: 20
    Timestamp logging: enabled
    Standby logging: disabled
    Debug-trace logging: disabled
    Console logging: disabled
    Monitor logging: disabled
    Buffer logging: disabled
    Trap logging: level errors, facility 20, 0 messages logged
        Logging to inside 172.31.252.63
    History logging: disabled
    Device ID: disabled
    Mail logging: disabled
    ASDM logging: level informational, 36911019 messages logged

Any ideas?
0
Comment
Question by:denver218
  • 3
  • 2
6 Comments
 
LVL 18

Expert Comment

by:Akinsd
ID: 39870312
Is 172.31.252.63 your KIWI server?

Show run logging
0
 
LVL 4

Author Comment

by:denver218
ID: 39870343
Yes it is my kiwi server and i can ping it from the ASA.

ASA5510# show run logging
logging enable
logging timestamp
logging trap errors
logging asdm informational
logging host inside 172.31.252.63
logging permit-hostdown
no logging message 106015
no logging message 313001
no logging message 313008
no logging message 106023
no logging message 710003
no logging message 106100
no logging message 302015
no logging message 302014
no logging message 302013
no logging message 302018
no logging message 302017
no logging message 302016
no logging message 302021
no logging message 302020
0
 
LVL 9

Accepted Solution

by:
ffleisma earned 250 total points
ID: 39870345
first check if logging server is reachable via ping 172.31.252.63

check if you are using the same UDP port 514 (although this is default) for the logging server and the ASA

another thing, which particular logs are you looking for on the syslog server? you might want to adjust the settings on the ACL you are trying to monitor and match it with the trap setting. i can see the trap logging is set to level errors. either adjust the logging level on the ACL or the trap level.

access-list inside_access_in line 1 extended permit ip any any log 3 interval 300
logging
hope this helps and let us know if you have any further questions
0
Threat Intelligence Starter Resources

Integrating threat intelligence can be challenging, and not all companies are ready. These resources can help you build awareness and prepare for defense.

 
LVL 18

Assisted Solution

by:Akinsd
Akinsd earned 250 total points
ID: 39870373
packet-tracer input inside udp ip.of.asa 514 172.31.252.63 514 de

Focus more on phase 2 (ACL).
That should tell if the ASA is filtering the packet
0
 
LVL 4

Author Closing Comment

by:denver218
ID: 39871230
Thanks guys, it works now.  I didn't change anything, but when I came back from lunch I saw logs from the ASA in the Kiwi server.  Its been sending logs since.  Thanks.
0
 
LVL 18

Expert Comment

by:Akinsd
ID: 39872073
Excellent!
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Join & Write a Comment

Suggested Solutions

Title # Comments Views Activity
Access shared drive during VPN session 9 65
cisco switch stacking 6 35
Sonicwall routing between VPNs 5 28
Access List 2 9
We've been using the Cisco/Linksys RV042 for years as: - an internet Gateway - a site-to-site VPN device - a leased line site-to-site subnet-to-subnet interface (And, here I'm assuming that any RV0xx behaves the same way as an RV042.  So that's …
Use of TCL script on Cisco devices:  - create file and merge it with running configuration to apply configuration changes
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

744 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now