Tuesday, May 21, 2019

Cisco ASA 5585-X logging monitor debugging question

I have Cisco ASA 5585-x running 9.x version, we have multiple ipsec VPN tunnel from many remote location, today one of tunnel not coming up so i am trying to debug but seeing very strange behavior, it must be configuration related.

debug crypto condition peer 34.22.13.45

debug crypto ikev1

logging monitor debugging <-- as soon as i run this command my SSH screen fill with many many logs related connection Built inbound / Teardown / TCP request etc.. even many more other kind of logs.. ( thousands of )

How do i see my vpn ipsec related logs in that mess? inshort i want to disable all other debugging and just keep vpn related debugging on..

asa-fw1/pri/act# show logging

Syslog logging: enabled

Facility: 20

Timestamp logging: enabled

Hide Username logging: enabled

Standby logging: disabled

Debug-trace logging: disabled

Console logging: disabled

Monitor logging: disabled

Buffer logging: level warnings, 778594470 messages logged

Trap logging: disabled

Permit-hostdown logging: disabled

History logging: disabled

Device ID: hostname "asa-fw1"

Mail logging: disabled

ASDM logging: level errors, 6709119 messages logged



No comments:

Post a Comment