cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
294
Views
0
Helpful
2
Replies

Security ACL with Syslog

Oscar Garza
Level 1
Level 1

Does anyone know how to send the denied statistics to a syslog server for a security acl? I am using -- set security acl ip IPACL1 deny tcp any any eq 135 log -- on the switch. When I run -- show security acl log flow tcp any any -- I see entries but they are never sent to my syslog server. I set the syslog server facility to 5. Any suggestions?

2 Replies 2

David Stanford
Cisco Employee
Cisco Employee

you should set logging to the appropriate level based on the message...ex)

%SEC-6-IPACCESSLOGP

Set logging to level 6 in this instance

you would also want to enter the command:

logging

Are any other syslog messages making it to the syslog server? If not, then it isn't set to reach the server correctly.

Syslog server is getting information about ports connecting and disconnecting.

I set the level to 6 and i will check syslog.

thanks

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card