05-06-2015 02:08 AM - edited 03-11-2019 10:53 PM
I have botfilter installed and running on an ASA5520 sw 9.1(5) ASDM 7.3(3).
The filter is active an detecting and blocking.
The Statistics in ASDM Monitoring is showing detections and blockings, the Infected Hosts is showing detections by host as expected.
But the real-time report in Monitoring in ASDM dosn't show anything.
Ány suggestions how to solve that?
regards Nikolaj
05-06-2015 03:57 AM
Hi,
Have you tried to check for these specific Syslog ID in the ASDM monitoring :-
338001 - 338004
338101 - 338104
338201 - 338204
338301 - 338310
Refer:-
http://www.cisco.com/c/en/us/td/docs/security/asa/syslog-guide/syslogs/logmsgs1.html#pgfId-5787165
Thanks and Regards,
Vibhor Amrodia
05-13-2015 01:03 AM
hi
I'm not quite following.
These ID's seems to notify detections etc regarding the BOT filter.
The ASA is detecting the BOT traffic and blocking and allowing.
My problem is that the ADSM doesn't update the "real-time report" in the ASDM interface.
05-13-2015 09:49 PM
Hi,
I am sorry. I misunderstood your question.
Upgrade to ASDM 7.4.1 and above to fix this Defect:-CSCuq59377
https://tools.cisco.com/bugsearch/bug/CSCuq59377/?reffering_site=dumpcr
Thanks and Regards,
Vibhor Amrodia
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: