Log Management of ASA Firewall
One of the most important functions of any firewall product is to log time, and ASA uses synchronous logging to record all times that occur on the firewall.
The security level of log information is divided into eight levels, as follows:
Configuration Log:
Log information can be output to log buffer (log buffer), ASDM, and log server.
Before configuring logs, you generally need to configure the time zone and time, and then configure log buffer, ASDM and log server respectively, as shown below:
Ciscoasa (config) # clock timezone beijing 8 # beijing is used to specify the name of the time zone. 8 refers to the offset from the international standard time. The value range is-23~+23ciscoasa (config) # clock set 13:12:00 30 april 2019 # configuration time, in the order of hours, minutes, seconds, day, month, and year.
Configure log buffer with the following command:
Ciscoasa (config) # logging enable ciscoasa (config) # logging buffered informational # configure informational level logs
The default size of log buffer is 4KB.
The command to view log buffer is as follows:
Ciscoasa (config) # show logging
The command to clear log buffer is as follows:
Ciscoasa (config) # clear logging buffer
Configure the ASDM log with the following command:
Ciscoasa (config) # logging enable ciscoasa (config) # logging asdm informational
The command to clear ASDM log buffer is as follows:
Ciscoasa (config) # clear logging asdm
Configure the log server:
At present, there are many log server software, it is recommended to use web-based firewall log analysis software: firewall analyzer 6, which supports Windows and Linux platforms.
Ciscoasa (config) # logging enableciscoasa (config) # logging timestamp ciscoasa (config) # logging trap informational ciscoasa (config) # logging host inside 192.168.1.1