Concentrator filterable event logs in ASA?

Unanswered Question
Oct 12th, 2008
User Badges:


On the concentrator it had a great tool caleld "filterable event logs" to see why users were having issues logging on the VPN and the same for the site-to-site links.

How can I do this on the ASA 5520?


  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
whiteford Tue, 10/14/2008 - 01:42
User Badges:

Thanks Andrew,

But how can I just show VPN related information?


whiteford Tue, 10/14/2008 - 02:02
User Badges:

I'm look for information as to when users put in incorrect passwords/username, or the SA's are wrong on a Site-to-Site tunnel etc, just like the concentrator did?

whiteford Tue, 10/14/2008 - 03:24
User Badges:

My real-time logger appears blank (debugging), but my log buffer (debugging) is full information but very slow, which should I use?

Farrukh Haroon Tue, 10/14/2008 - 06:18
User Badges:
  • Red, 2250 points or more

You can also create a logging list for a particular 'class' like FAILOVER, VPNs etc. and then either send it to syslog/email etc. or raise its level to something very low (like level 1 or2). Then just turn on buffer logging or monitor logging for that particular level. This way you will filter all the level 4/5/6 messages of permit/deny/acl logging.




This Discussion