10Mb Metro link between ASA 5505 and ASA 5510

Dear all,

I have encountered one difficult problem, I wished all expert could give my - newie some tips,


One ASA 5505 - ASA 7.2(1) and ASDM 5.2(1)

One ASA 5510 - ASA 7.2 (1) and ASDM 5.2(1)

These two firewall make site-to-site VPN connection

two ASA has three interface - the one is inside (security level is 100), the another is outside (security level is 0), the finally interface is metro (security level is also 100)

***** I didn't know why around 3 days to one week , these two ASA would hang and make all internal PC cannot access to internet, it need to uplug and replug power, and then the ASA resumed. I didn't know how to shooting this problem, is ASA version is old (7.2(1)), or other problem,

***** I didn't know how to see the log, in the matter of fact, I have already set up a syslog in the one windows server, but I see log, I found no any error log for ASA error or hang message, please everyone.


Re: 10Mb Metro link between ASA 5505 and ASA 5510

To see the error logs on ASA; telnet to the device and after authentication give command "show log". This will display a long list of log messages. Point out to the log messages that have been logged at the time when the connection went down. Without the error message or syslog message it would not be possible to figure out the problem. Following link may help you to configure ASA for syslog

Re: 10Mb Metro link between ASA 5505 and ASA 5510

Just out of curiosity, but is your ASA5505 licensed correctly? I.E. is it only a 10 user license, but you have 15 internal hosts behind it?

