Showing posts with label Syslog. Show all posts
Showing posts with label Syslog. Show all posts

04 May, 2015

ASA Device Manager (ASDM) Management and Syslog


ASA(config)# show mode
Security context mode: single
ASA(config)# show firewall
Firewall mode: Router

! Configure Interfaces Gi0,Gi1 i Gi3
ASA(config)# in g 1
ASA(config-if)# no shu
ASA(config-if)# nameif inside
ASA(config-if)# ip address 10.0.0.254 255.255.255.0
ASA(config-if)# security-level 100
ASA(config-if)# ping 10.0.0.1
!!!!!

ASA# show ip
System IP Addresses:
Interface                Name                   IP address      Subnet mask     Method
GigabitEthernet0         ouside                 192.168.0.254   255.255.255.0   manual
GigabitEthernet1         inside                 10.0.0.254      255.255.255.0   manual
GigabitEthernet2         dmz                    20.0.0.254      255.255.255.0   manual

ASA# show nameif
Interface                Name                     Security
GigabitEthernet0         ouside                     0
GigabitEthernet1         inside                   100
GigabitEthernet2         dmz                       50

! Configuration to support ASDM
ASA(config)# http server enable
ASA(config)# http 192.168.0.0 255.255.255.0 ouside
ASA(config)# http 0 0 ouside ! (Permit Any IP)
ASA(config)# username admin password cisco priv 15

ASA(config)# show flash: | in asdm
   89  18927088    May 04 2015 13:48:32  asdm-649.bin

ASA(config)# asdm image flash:/asdm-649.bin


! Configure OSPF in GUI ASDM





! After Apply config Check CLI
ASA(config)# show run router
!
router ospf 1
 network 10.0.0.254 255.255.255.255 area 0
 network 20.0.0.254 255.255.255.255 area 0
 network 192.168.0.254 255.255.255.255 area 0
 area 0
!

! Check R1 OSPF Process R1#show ip route ospf
O        2.2.2.2 [110/12] via 10.0.0.254, 00:49:46, FastEthernet0/0
O        3.3.3.3 [110/12] via 10.0.0.254, 00:49:46, FastEthernet0/0
O        20.0.0.0 [110/11] via 10.0.0.254, 00:49:46, FastEthernet0/0
O     192.168.0.0/24 [110/11] via 10.0.0.254, 00:49:46, FastEthernet0/0

R1#tel 3.3.3.3
Trying 3.3.3.3 ... Open
R3>

R1#tel 2.2.2.2
Trying 2.2.2.2 ... Open
R2>

ASA(config)# show conn all
7 in use, 14 most used
OSPF ouside 224.0.0.5 NP Identity Ifc192.168.0.254, idle 0:00:03, bytes 1540
OSPF dmz 224.0.0.5 NP Identity Ifc20.0.0.254, idle 0:00:04, bytes 1900
OSPF inside 224.0.0.5 NP Identity Ifc10.0.0.254, idle 0:00:02, bytes 1364
TCP ouside 192.168.0.100:49194 NP Identity Ifc 192.168.0.254:443, idle 0:00:00, bytes 409853, flags UOB  ! (ASDM Connection)
OSPF inside 10.0.0.1 NP Identity Ifc224.0.0.5, idle 0:00:01, bytes 2120
OSPF ouside 192.168.0.3 NP Identity Ifc224.0.0.5, idle 0:00:03, bytes 2040
OSPF dmz 20.0.0.2 NP Identity Ifc224.0.0.5, idle 0:00:09, bytes 2104

ASA(config)# show route | in O
       D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area
       N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2
       E1 - OSPF external type 1, E2 - OSPF external type 2, E - EGP
       * - candidate default, U - per-user static route, o - ODR
O    1.1.1.1 255.255.255.255 [110/11] via 10.0.0.1, 0:51:26, inside
O    2.2.2.2 255.255.255.255 [110/11] via 20.0.0.2, 0:51:26, dmz
O    3.3.3.3 255.255.255.255 [110/11] via 192.168.0.3, 0:51:26, ouside


ASA(config)# ping 1.1.1.1
!!!!!
ASA(config)# ping 2.2.2.2
!!!!!
ASA(config)# ping 3.3.3.3
!!!!!

! Enable/Disable Log Message by Number.

ASA(config)# logging on
ASA(config)# logging console 7
ASA(config)# show arp
        inside 10.0.0.1 ca00.0510.0008 6054
        dmz 20.0.0.2 ca03.0840.0008 3831
        ouside 192.168.0.100 0200.4c4f.4f50 1
        ouside 192.168.0.3 ca06.0840.0008 2239
%ASA-7-111009: User 'enable_15' executed cmd: show arp

ASA(config)# no logging message 111009
Or

ASA(config)# show arp
        inside 10.0.0.1 ca00.0510.0008 6152
        dmz 20.0.0.2 ca03.0840.0008 3928
        ouside 192.168.0.100 0200.4c4f.4f50 18
        ouside 192.168.0.3 ca06.0840.0008 2336
! Not Generates Log Message

04 August, 2014

NTP,Syslog,SNMPv3

Keeping Track of the Network

- NTP 
- Logging
- SNMPv3

# NTP

R1#show clock
*14:23:17.119 UTC Mon Aug 4 2014

! Change time zone
R1(config)#clock timezone PST -8

R1(config)#clock summer-time PDT recurring

! Configure NTP Server
R1(config)#ntp server 38.229.71.1

! For Debug Use: 
R1#debug ntp packets

! Verify NTP server configuration 
R1#show ntp associations
      address         ref clock     st  when  poll reach  delay  offset    disp
*~38.229.71.1      204.123.2.72      2    59    64  377   135.8   -1.20     1.0
* master (synced), # master (unsynced), + selected, - candidate, ~ configured

R1#show ntp associations detail
38.229.71.1 configured, our_master, sane, valid, stratum 2
ref ID 204.123.2.72, time D789FAD1.1ACDEE21 (12:28:01.104 UTC Mon Aug 4 2014)
our mode client, peer mode server, our poll intvl 64, peer poll intvl 64
root delay 54.52 msec, root disp 22.20, reach 377, sync dist 119.720
delay 135.85 msec, offset -1.1982 msec, dispersion 2.33
precision 2**20, version 3
org time D789FB2C.A11B70B4 (12:29:32.629 UTC Mon Aug 4 2014)
rcv time D789FB2C.C27C97CA (12:29:32.759 UTC Mon Aug 4 2014)
xmt time D789FB2C.8B331998 (12:29:32.543 UTC Mon Aug 4 2014)
filtdelay =   215.19  139.95  143.98  139.95  139.50  135.85  135.88  135.83
filtoffset =  -22.79   -2.95    1.56    0.30   -0.32   -1.20   -0.26    0.16
filterror =     0.02    0.99    1.01    1.02    1.04    1.05    1.07    1.08

R1#show ntp status
Clock is synchronized, stratum 3, reference is 38.229.71.1
nominal freq is 250.0000 Hz, actual freq is 250.0000 Hz, precision is 2**18
reference time is D789FB2C.C27C97CA (12:29:32.759 UTC Mon Aug 4 2014)
clock offset is -1.1982 msec, root delay is 190.37 msec
root dispersion is 25.74 msec, peer dispersion is 2.33 msec

! If using Authentication
R1(config)#ntp update-calendar
R1(config)#ntp authentication-key 1 md5 cisco123
R1(config)#ntp authenticate
R1(config)#ntp trusted-key 1
R1(config)#ntp server x.x.x.x key 1 source fas0/0 prefer

# Logging 

R1(config)#logging on
R1(config)#logging buffered informational
R1(config)#logging host 192.168.1.129
R1(config)#logging trap debugging

R1(config)#do show logging
Syslog logging: enabled (12 messages dropped, 0 messages rate-limited,
                0 flushes, 0 overruns, xml disabled, filtering disabled)
No Active Message Discriminator.
No Inactive Message Discriminator.
    Console logging: level debugging, 261 messages logged, xml disabled,
                     filtering disabled
    Monitor logging: level debugging, 0 messages logged, xml disabled,
                     filtering disabled
    Buffer logging:  level informational, 261 messages logged, xml disabled,
                     filtering disabled
    Logging Exception size (8192 bytes)
    Count and timestamp logging messages: disabled
    Persistent logging: disabled
No active filter modules.
ESM: 0 messages dropped
    Trap logging: level debugging, 25 message lines logged
        Logging to 192.168.1.129  (udp port 514,  audit disabled,
              authentication disabled, encryption disabled, link down),
              0 message lines logged,
              0 message lines rate-limited,
              0 message lines dropped-by-MD,
              xml disabled, sequence number disabled
              filtering disabled
Log Buffer (8192 bytes):

# SNMP

! Create access list for SNMP
R1(config)#access-list 10 permit 192.168.1.129
R1(config)#access-list 10 deny any log
R1(config)#do show access-list
Standard IP access list 10
    10 permit 192.168.1.129
    20 deny   any log

! Configure SNMP v3 
R1(config)#snmp-server engineID local 123456789A
R1(config)#snmp-server group G1 v3 priv access 10

* Note: 
  auth    (Authentication, No Encryption)
  noauth  (No Authentication, No Encryption)
  priv    (Authentication, Encryption)
  
Create User 
R1(config)#snmp-server user U1 G1 v3 auth sha a-Pass priv aes 128 e-Pass
Aug  4 13:35:23.133: Configuring snmpv3 USM user, persisting snmpEngineBoots. Please Wait...

* Note: This configuration do not save in running-config
R1(config)#do show run | in U1
Blank

! To Verify SNMP user
R1(config)#do show snmp user
User name: U1
Engine ID: 123456789A
storage-type: nonvolatile        active
Authentication Protocol: SHA
Privacy Protocol: AES128
Group-name: G1

! Configure SNMP Host
R1(config)#snmp-server host 192.168.1.129 traps version 3 auth U1
R1(config)#snmp-server enable traps syslog

! Configure ManageEngine MibBrowser
* Note: Use free SNMP (ManageEngine MIB Browser)

! Verify CPU Usage
R1(config)#do show proce cpu sor | in ^CPU|SNMP ENGINE
CPU utilization for five seconds: 14%/100%; one minute: 13%; five minutes: 6%
 233        8932      1044       8555  0.00%  4.77%  2.36%   0 SNMP ENGINE

*Note: SNMP is configured and Works fine

! Check Encryption using Wireshark
! Capture SNMP Traffic 
* Note : All SNMP packets are Encrypted

! Configure Wireshark with User and Pass to see Content of SNMP

Steep 1:
Steep 2:
Steep 3:
* Note : Now we can read information from SNMP Packets.

04 October, 2013

Install and configure SysLog Server in Debian and Cisco

#Download SysLog Server
apt-get install sysklogd -y

#Change Configuration 
vi /etc/default/syslogd

add SYSLOGD="-r"
Note: -r = Recive Remote Logs

#Configure syslog.conf file Add this line
vi /etc/syslog.conf

local7.debug         /syslog/remote.log 

Note: Where /syslog/remote.log is syslog file 

Other way


daemon.*;mail.*;\
        news.err;\
        *.=debug;*.=info;\
        *.=notice;*.=warn       |/dev/xconsole

*.* /var/log/network/network.log
#*.* /var/log/network/%HOSTNAME%.log
#:msg, contains, "dsw1"  /var/log/network/DSw1.log

:fromhost-ip,isequal,"10.0.10.11" /var/log/network/ASw1.log
:fromhost-ip,isequal,"10.0.10.12" /var/log/network/ASw2.log
:fromhost-ip,isequal,"10.0.10.13" /var/log/network/ASw3.log
:fromhost-ip,isequal,"10.0.10.14" /var/log/network/ASw4.log
:fromhost-ip,isequal,"10.0.10.1" /var/log/network/DSw1.log
:fromhost-ip,isequal,"10.0.10.2" /var/log/network/DSw2.log
:fromhost-ip,isequal,"10.0.5.1" /var/log/network/iNetR1.log
:fromhost-ip,isequal,"10.0.5.2" /var/log/network/iNetR2.log
:fromhost-ip,isequal,"10.1.1.1" /var/log/network/remote1.log
:fromhost-ip,isequal,"10.1.2.1" /var/log/network/remote2.log
:fromhost-ip,isequal,"10.1.3.1" /var/log/network/remote3.log
:fromhost-ip,isequal,"10.1.4.1" /var/log/network/remote4.log

#Restart Service 
/etc/init.d/sysklogd restart

#Check if Syslog is on 
ps -ef | grep syslog
netstat -a | grep syslog

#Configure Cisco Device 
configure terminal
logging source-interface [interface]
logging <ip address of your Debian system>
logging trap debug
logging on 
service timestamps log datetime msec localtime show-timezone
ntp-server <ntp-server>


Done !