Cisco Firewall :: ASA 5510 - Log Reporting During Large Period
Apr 23, 2013
I'm using ASA 5510 and I wondered if we can configure reporting to know the traffic on each interface,the attacks,the vpn connection during a period ( 1 week or 1 month). For the moment, we can see these logs only in 'real time' .
we have a customer with a ASA 5510 with a CSC module in it. The device tells us the Base license has expired. The new license has been renewed - after - the grace period. The Trendmicro site tells us the Base license is valid until 21 october 2013 but the CSC refuses to acknowledge this. The module is able to fetch updates form the Internet so it does not look like a connection problem to me (it also has a plus license which is also valid till far into 2013 and that one works).Is it possible that the current license key is "dead" and the CSC expects a new license key because the grace period was expired?
I am attempting to FTP to a remote site through a IPSEC tunnel.When I am transfering large files the ASA5540 is showing syslog errors stating "connection timeout". What I think is happening is after about 1 hour the firewall is closing the connection control port for the FTP session and neither end is notified so eventually the transfer is stopped.What do I need to modify in the FW to accommodate these larger files?
Is there any way to get reports on voice utilisation on WAN links so that CAC settings can be proactively managed for each location on our CUCM cluster? Our service provider is advising that this is not possible which means that we rely on customer/staff complaints to recognise where CAC thresholds are being reached. Our preference is to be able to run traffic reports (or the Cisco equivalent) as could be done on our previous (traditional) telephony network and provide additional capacity if and when required BEFORE congestion is reached, thus minimising customer/staff impact.
Runing the report, "CleanAir > Worst Interferers" and I get this error
The specified criteria did not match any data for the report. Make sure that the following background tasks are running: 1. Interferers
I know there is data that should match up because I can see it on the individual controllers. I checked the background task Interferers and it appears to be working as well but just to make sure I forced the "Execute Now" command but the report still failed.
WCS is reporting few AP's are not associated with it. While troubleshooting, AP conneceted switch interface shows UP/UP and show power inline output gives IEEE PD instead of AIR-LAP1131AG-E-K, after doing a shut/no shut on AP connected interface. Later after sometime AP comes up.
I'm currently running Cisco LMS 4.1. I need to see if there is a way in the LMS, either through the menu or via a report, that can give me the V LAN numbers, the description, the IP address, the Interface (SVI) the v LAN is on and the route it takes.
I've searched near and far and haven't come up with anything yet.
we are running WCS 7.0.164.3 and wonder whether is there any reporting option availabel that can give us daily report on Top 50 or Top 100 APs by client count.
I know that I can look at the client tab under WCS home page and see the top 5 APs by client count on real time.In our environment we have around 700 APs and would like to know by having this kind of report which APs are mostly hit ?
I have not managed to get the Monitoring to work on the ACS 5.1. This is an eval version. Advanced monitoring and reporting is installed on the ACS. This is my configuration on the Cisco Router
aaa accounting exec default start-stop group tacacs+aaa accounting commands 0 default start-stop group tacacs+aaa accounting commands 1 default start-stop group tacacs+aaa accounting commands 15 default start-stop group tacacs+aaa accounting connection default start-stop group tacacs+ logging origin-id iplogging facility sysloglogging source-interface GigabitEthernet1/1logging host 1.1.1.1 transport udp port 20514 logging monitor informational epm logging
On the ACS, when I open the dashboard --> ACS health -> I get Status not available.Global Instance under Logging Categories been configured for local logging?
I have Windows XP Pro SP3. After a random period of maybe 30 mins to a few hours, my internet connection seems inexistant. PC reacts like there is no internet cable plugged in. I've checked the ipconfig command in command prompt before my internet shuts down and after and there was a change. A few lines(IPs) were missing after my internet fell.
I just upgraded yesterday to the DIR-655 (ver B1, F/W Ver 2.00NA), and suddenly my sons Xbox 360 complains that the NAT is set to moderate. I'm not really sure what this means, but I've never seen it before and it wasn't an issue with my old router. It pertains to the DIR-655? I did some quick google searches and I've seen lots of different 'solutions' to this issue, but none of them seem to agree with each other and I'd rather not spend and entire afternoon trying one after another given that this router kills my internet connection for a full 20 seconds every single time I make any change.
We have a VPN 3000 that we use to connect. We are recieving reports that some of the users are connected but after a set period of time they are disconnected. Is there any changes that I could look at in the VPN 3000 that could point me in the right direction.
we have installed an evaluation version of Cisco Works LMS 4.0.1. Now we have purchased a license, but the evaluation period is over and I can't start the application anymore. Is there any possibility to install the license file after the evaluation period?
We have discovered Nortel/HP C-GbE2 switches on our network are sending spanning tree Topology Change Notifications (TCN). The HP switches only have servers connected and no other switches leading to any other network segment so we are not clear why the switches are sending spanning tree TCNs every second. We do not have a support contract. Can anyone on the Cisco side speak to what's referenced on page 5-6 of the attached document? I found the attached document which talks about diabling spanning-tree (page 5-6) in Cisco environment but wanted to consult with an expert before proceding. Document (Configuring Nortel Gigabit Ethernet Switch Modules for IBM BladeCenter in a Cisco Environment Solution Brief.
I noticed one awkward thing with the latest 1.0.3.5 firmware for the Cisco Small Business RV220W router, with previous firmwares there has always been reported 128mb of system memory (RAM) under the router dashboard. And several "teardowns" of this router has confirmed it to have 128mb of memory on the router board.
Does that mean the latest 1.0.3.5 has an odd visual bug, or has the RV220W gotten it's memory sliced in half with this firmware release?
I'd like to know if there is a way to exclude passed authentications for a specific username from reporting in the Authentications-TACACS and Authentications-RADIUS reports?
We have a few usernames that are used in scheduled jobs. We only need to know when they fail authentication, so we don't need to fill up the reports with every passed authentication from these accounts. Can this be done?
We have 2 ASA 5505 located in head office (173.212.xxx.xxx) and remote site (50.34.xxx.xxx) and site-to-site VPN has been established between them.everything is fine but the ASA in head office keeps reporting below 402120 syslog message.
4 Jan 02 2013 12:30:34 402120 50.34.xxx.xxx 173.212.xxx.xxxIPSEC: Received an ESP packet (SPI= 0x384E1C57, sequence number= 0x2AE77) from 50.34.xxx.xxx(user= ) to 173.212.xxx.xxx that failed authentication.
I have a Cisco 2911 router with 4 T1 connections. Two are set as a multilink and the other two are for two other locations. The router will run fine, but after a month I cannot ping the gigabit ethernet 0/0 interface. I would have to manually reboot the router to get it to respond again. Before I noticed a lot of interface discards which would shutdown the 2911 and a manual reboot would be needed, but for this time it isn't the case. Where would I start with this the memory and cpu usage are fine.
Here is the config: Current configuration : 2905 bytes ! version 15.0
I have a question about managing the Access Point:
-WLC2504 -AIR-LAP1262N-A-K9
First: I need the access point works by period, example: 08:00AM - 06:00PM after that disable the radio and return work next day at 08:00AM
Second: Also, if the radio no activity for a long period (e.g 60 or 120 minutes), disable the radio interface.It's possible with the WLC? Or maybe need implement one NCS?EnergyWise Technology - but, I only need "shutdown" the radio not the Access Point completely.
1) How do you manage your inventory of network equipment from the time you receive a product into inventory to the time you decommission it?
2) How do you make aware the people who manage your network monitoring/reporting software that a device has been added/removed from the field?
2a) How do you notify the people who manage your network monitoring/reporting software of what is to be monitored on a new device in the field? Of a new interface that has been added/removed on an existing device?
2b) How quickly do you notify for 2/2a? i.e. minutes, hours, days, etc.
3) What types of interfaces and resources do you monitor on a network device?
I have just gotten a new touch phone that has wifi. and i wanna use it through my dlink dir-825 router. My phone is the nexus s with 2.3 andriod OS.The problem is that my phone can see the 2.4 ghz connection it just keeps reporting "deactivated" i did acess other wifi and used the internet over a router. So i know the phone works.
So my question is: 1. Can i make my router ONLY be in 2.4ghz mode, if so, can you link or explain it?
I am configuring new ACS 1121 appliance with version 5.3 and wanted to know how to configure Remote Database settings in ACS5.3 Is that necessary to configure that option ?
Also one more thing I can see that ACS 5.3 generates lots of logs is there any solution to reduce such logs. It seems many unuseful logs which are system related are getting logged into device which might no be good for memory requirements of device.
Every other day and sometimes everyday I have an issue where my network slows down in one area at around the same time of day 12:00pm. I am using Solarwinds and I don't see anything significant showing up.
I have a new Win 7 Dell Precision Workstation that will not log in to my domain. I get an error that there is no login server available if I attempt to log in using a domain account. I log in as the local admin and then try to join a domain using the Join a Domain or Workgroup wizard. I then get an error stating "this operation returned because the timeout period expired". I have had to reset my core switch to get a couple of the new boxes (including this one) to even join the domain. I also show no internet in the Network and Sharing Center most of the time.
So, I just upgraded my mobo/cpu (Z77A-G45 and i5-2500k) and I'm having an issue with my connection as it seems to drop every 5 to 15 minutes constantly and have no idea what exactly is wrongThe kicker is my old mobo did the same thing and I had to do something in win7 to fix it (not sure if it was the drivers or what) but I just can't remember what exactly.
My XP Pro SP3 PC is connected to a Netgear DG834N modem/router via Ethernet. If the PC is left for say 4-5 hours the ability to connect to websites disappears. The browser just hangs and it's the same with IE and Firefox The odd thing is I can still ping websites by domain name without trouble. So the interenet connection is actually still in place.The problem is consistent and repeatable.Throughout this I have a second XP Pro SP3 PC also connected to the router via Ethernet and it works perfectly.
We have a pair of 6509 working in a VSS configuration (IOS 12.2(33)SX5). The 6509s connect to a pair of ASAs (7.2 code) running in an Active/Standby setup. These ASAs in turn connect to routers going to remote sites. I have configured Netflow on the following VLANS,
VLAN 10 - Servers Vlan VLAN 9 - Transit/ASA VLAN (connects ASAs to 6509s). All traffic originating from any VLAN on the 6509 crosses this VLAN in order to reach remote sites and vice versa
I configured the netflow source VLAN 11 although I am not collecing any netflow from it.Although I have been getting lots of Netflow info, I noticed that netflow for traffic originating from any user VLAN on the 6509s going to any remote site via TRANSIT/ASA VLAN(9) does not get reported, I even tested with 4 GB traffic but no result. Only reverse traffic (i.e. from remote site to user VLAN) is reported as it traverses the Transit VLAN (9).
I read somewhere that egress netflow is not supported in 6500, but isnt traffic originating from a user vlan to a remote site via the transit VLAN (9) considered ingress with respect to the transit VLAN (9)? I would like to know whether bidirectional Netflow is supported on 6500 VLANS. I have mimimum control on routers beyond the ASAs, and since these ASAs run 7.2 code netflow is not supported, and Monitoring this Transit Vlan gives me extremely useful info.
I do get netflow biderectional traffic from the Server Vlan 10, but I think it is correlated by the netflow collector from vlans 9 and 10. [code]
I have a D610 Laptop with integrated Bluetooth and Wifi. The evaluation period has expired. Please obtain a license for this version of Bluetooth Stack for Windows by Toshiba."
I had called Gold Support last week and was asked to download/install the driver from the support downloads site and then download/install the patch as well. The bluetooth manager does not come up when this popup shows.
Just replaced a WRT54GS with an E2500. It seems that anytime a connected device goes "idle" for a while, the connection breaks or severely reduces and it's nearly impossible to get the connection back without performing an action at the device in question. Let the wireless connection on my laptop go unused for some period and it reduces to 1Mbps and you can't get back on by just using the link more... you have to do a "repair".
Let more than a few minutes pass since you've printed something on the wireless printer and you MUST go to the printer to re-establish the connection by turning the antenna off and then on again.Basically the same problem with my blueray/DVD getting on the network. When I shut the screen off on my phone, the wifi dies and receives NOTHING over that link while the screen is off.
None of these behaviors existed with the WRT... just the 2500. Background/facts - current firmware, DHCP with reservations, WPA2/per, MAC filtering in use, UPnP disabled. MTU/Beacon/Frag threshold/RTS threshold set per recommendations on this site.