Cisco ASA logging best practices (2024)

Table of Contents
Related articles Comments

Cisco ASA logging best practices (1)

Charles B

  • Updated
Follow

For the best results with Cisco ASA logging, the device should be configured to send 106100 messages and the legacy messages 302013 and 302015 should be disabled.

ASA devices have a global level and a rule level logging option, the rule level logging is enabled by adding the "log" keyword to the end of each ACL.

Global logging are the legacy messages 302013 and 302015. These are built up connection messages for TCP and UDP connections respectively.

The legacy messages (302013/302015) are UDP and TCP only. As such usage for other protocols like ICMP will not be matched.

Rule level logging (106100) is matched using the hex ID for each ACL and message.

2021-06-16 03:15:57,583 [0x7fd9237fe700] DEBUG SyslogUdpServer - [40VH9C] Received message [m-3-001k] from [10.250.0.190]: [<166>%ASA-6-106100: access-list inside_access_in permitted tcp inside/10.250.0.200(41022) -> ext-net/192.168.0.11(80) hit-cnt 1 first hit [0x1c834070, 0xd759e618]\n]

access-list inside_access_in line 2 extended permit ip 10.250.0.0 255.255.255.0 object-group server_group log informational interval 300 0x1c834070
access-list inside_access_in line 2 extended permit ip 10.250.0.0 255.255.255.0 host 192.168.0.10 log informational interval 300 (hitcnt=5) 0x17220ecd
access-list inside_access_in line 2 extended permit ip 10.250.0.0 255.255.255.0 host 192.168.0.11 log informational interval 300 (hitcnt=35) 0xd759e618
access-list inside_access_in line 2 extended permit ip 10.250.0.0 255.255.255.0 host 192.168.0.12 log informational interval 300 (hitcnt=25) 0x8bcaa964

Legacy messages require more processing to match as they have no unique identifiers.

To avoid both 106100 and legacy messages being counted twice for each rule hit, you should disable the legacy ones with these commands

no logging message 302013
no logging message 302015

Other message types should also be disabled to reduce the load on the DC, as those messages will be discarded.

Traffic Flow Analysis (TFA) requires syslog, it will not work with hit counters.

Hit counters uses the hitcnt number from the "show access-list" command.

access-list ext-net_access_in line 3 extended permit ip any any log informational interval 300 (hitcnt=0) 0x3b105d4e

This does not provide any detail into the actual traffic passed by the rule.

If objects on the ASA are configured using the "names" method, then you must run "no names".

If names is enabled, then the ASA sends those in the usage message and then it can not be matched. As a result, the TFA data will not be complete and report 0.0.0.0 rather than the actual flow data.

Related articles

Comments

1 comment

  • Cisco ASA logging best practices (2)

    James Ceresia

    This is an *excellent* article and bit of knowledge!

    Comment actions Permalink

Please sign in to leave a comment.

Cisco ASA logging best practices (2024)
Top Articles
Can you use scalping signals with Binance? » FX Leaders
100+ Taylor Swift Eras Tour Outfit Ideas & What to Wear to A Taylor Swift Concert!
English Bulldog Puppies For Sale Under 1000 In Florida
Katie Pavlich Bikini Photos
Gamevault Agent
Pieology Nutrition Calculator Mobile
Hocus Pocus Showtimes Near Harkins Theatres Yuma Palms 14
Hendersonville (Tennessee) – Travel guide at Wikivoyage
Compare the Samsung Galaxy S24 - 256GB - Cobalt Violet vs Apple iPhone 16 Pro - 128GB - Desert Titanium | AT&T
Vardis Olive Garden (Georgioupolis, Kreta) ✈️ inkl. Flug buchen
Craigslist Dog Kennels For Sale
Things To Do In Atlanta Tomorrow Night
Non Sequitur
Crossword Nexus Solver
How To Cut Eelgrass Grounded
Pac Man Deviantart
Alexander Funeral Home Gallatin Obituaries
Energy Healing Conference Utah
Geometry Review Quiz 5 Answer Key
Hobby Stores Near Me Now
Icivics The Electoral Process Answer Key
Allybearloves
Bible Gateway passage: Revelation 3 - New Living Translation
Yisd Home Access Center
Pearson Correlation Coefficient
Home
Shadbase Get Out Of Jail
Gina Wilson Angle Addition Postulate
Celina Powell Lil Meech Video: A Controversial Encounter Shakes Social Media - Video Reddit Trend
Walmart Pharmacy Near Me Open
Marquette Gas Prices
A Christmas Horse - Alison Senxation
Ou Football Brainiacs
Access a Shared Resource | Computing for Arts + Sciences
Vera Bradley Factory Outlet Sunbury Products
Pixel Combat Unblocked
Movies - EPIC Theatres
Cvs Sport Physicals
Mercedes W204 Belt Diagram
Mia Malkova Bio, Net Worth, Age & More - Magzica
'Conan Exiles' 3.0 Guide: How To Unlock Spells And Sorcery
Teenbeautyfitness
Where Can I Cash A Huntington National Bank Check
Topos De Bolos Engraçados
Sand Castle Parents Guide
Gregory (Five Nights at Freddy's)
Grand Valley State University Library Hours
Hello – Cornerstone Chapel
Stoughton Commuter Rail Schedule
Nfsd Web Portal
Selly Medaline
Latest Posts
Article information

Author: Otha Schamberger

Last Updated:

Views: 6191

Rating: 4.4 / 5 (55 voted)

Reviews: 86% of readers found this page helpful

Author information

Name: Otha Schamberger

Birthday: 1999-08-15

Address: Suite 490 606 Hammes Ferry, Carterhaven, IL 62290

Phone: +8557035444877

Job: Forward IT Agent

Hobby: Fishing, Flying, Jewelry making, Digital arts, Sand art, Parkour, tabletop games

Introduction: My name is Otha Schamberger, I am a vast, good, healthy, cheerful, energetic, gorgeous, magnificent person who loves writing and wants to share my knowledge and understanding with you.