Concentrator filterable event logs in ASA?

Unanswered Question
Oct 12th, 2008

Hi,

On the concentrator it had a great tool caleld "filterable event logs" to see why users were having issues logging on the VPN and the same for the site-to-site links.

How can I do this on the ASA 5520?

Thanks

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
whiteford Tue, 10/14/2008 - 01:42

Thanks Andrew,

But how can I just show VPN related information?

Thanks

whiteford Tue, 10/14/2008 - 02:02

I'm look for information as to when users put in incorrect passwords/username, or the SA's are wrong on a Site-to-Site tunnel etc, just like the concentrator did?

Farrukh Haroon Tue, 10/14/2008 - 06:18

You can also create a logging list for a particular 'class' like FAILOVER, VPNs etc. and then either send it to syslog/email etc. or raise its level to something very low (like level 1 or2). Then just turn on buffer logging or monitor logging for that particular level. This way you will filter all the level 4/5/6 messages of permit/deny/acl logging.

Regards

Farrukh

Actions

This Discussion