cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
654
Views
0
Helpful
2
Replies

How to label the traffic log which hit access-list?

Machi Ma
Level 1
Level 1

Hello,

 

I have created a access-list rules which using to bypass VPN-like traffic to SFR. 

 

And I would like to do summaries of them at syslog.  Could you please advise how can I process it?

 

There are various of access-list group and I just want to record "asasfr-servicetype" to syslog if it bypass. 

 

Following please find the section of access-list

======

access-list asasfr-servicetype remark bypass https service to SFR
access-list asasfr-servicetype extended deny tcp any any eq https log inactive
access-list asasfr-servicetype remark bypass gre traffic to SFR
access-list asasfr-servicetype extended deny gre any any log
access-list asasfr-servicetype remark bypass PPTP traffic to SFR
access-list asasfr-servicetype extended deny tcp any any eq pptp log
access-list asasfr-servicetype remark bypass IKEv2 (IPSec control path)
access-list asasfr-servicetype extended deny udp any any eq isakmp log
access-list asasfr-servicetype remark bypass IKEv2 (IPSec control path)
access-list asasfr-servicetype extended deny udp any any eq 4500 log
access-list asasfr-servicetype remark L2TP control/data path
access-list asasfr-servicetype extended deny udp any any eq 1701 log
access-list asasfr-servicetype remark Bypass ipinip traffic into SFR
access-list asasfr-servicetype extended deny ipinip any any log
access-list asasfr-servicetype remark Allow others traffic exclude above rule
access-list asasfr-servicetype extended permit ip any any

 

class-map asasfr-test
 match access-list asasfr-servicetype

 

=========

 

Thanks in advance.

 

 

2 Replies 2

Hi @Machi Ma

 

Do you have this on your ASA ?

 

logging userinfo
logging event link-status default
logging trap notifications
logging source-interface "Interface"
logging  "Syslog server"
logging trap information 

 

-If I helped you somehow, please, rate it as useful.-

Hello,

 

Only I have following part:

==============================

logging enable
logging timestamp
logging trap warnings
logging asdm informational
logging host management 192.168.0.211
logging class auth trap informational
no logging message 106015
no logging message 313001
no logging message 313008
no logging message 106023
no logging message 710003
no logging message 106100
no logging message 302015
no logging message 302014
no logging message 302013
no logging message 302012
no logging message 302018
no logging message 302017
no logging message 302016
no logging message 302021
no logging message 302020
logging rate-limit unlimited level 1
logging rate-limit unlimited level 4
logging rate-limit unlimited level 6
logging rate-limit 50 1 message 434004
logging rate-limit 50 1 message 434002
logging rate-limit 50 1 message 401004
logging rate-limit 50 1 message 400026
logging rate-limit 50 1 message 400011

-==============================

 

Could you please further explain what should I do it?

 

Thanks!

Review Cisco Networking for a $25 gift card