Logging, Monitoring & Troubleshooting
Cisco ASA Firewall EVE-NG — ASAv (CLI + ASDM)
مقصدObjectiveObjective
صحیح severity پر buffered اور syslog logging کنفیگر کریں، ASDM monitoring views use کریں، اور troubleshooting کے لیے packet-tracer tool میں ماہر بنیں۔Sahi severity par buffered aur syslog logging configure karo, ASDM monitoring views use karo, aur troubleshooting ke liye packet-tracer tool mein mahir bano.Configure buffered and syslog logging at the right severity, use ASDM monitoring views, and master the packet-tracer tool for troubleshooting.
آسان مثالSimple AnalogySimple Analogy
Logging گارڈ کی diary ہے: level 1 entries emergencies ہیں ('آگ!')، level 7 ہر چھوٹی detail ہے ('کوئی پلک جھپکا')۔ Packet-tracer گارڈ سے کہنا ہے کہ visitor کے آنے سے پہلے step by step بتائے وہ اس کے ساتھ کیا کرے گا۔Logging guard ki diary hai: level 1 entries emergencies hain ('aag!'), level 7 har choti detail hai ('koi palka jhapka'). Packet-tracer guard se kehna hai ke visitor ke ane se pehle step by step bataye woh uske sath kya karega.Logging is the guard's diary: level 1 entries are emergencies ('fire!'), level 7 is every tiny detail ('someone blinked'). Packet-tracer is asking the guard to walk you through exactly what he would do with a visitor, step by step, before the visitor arrives.
سیٹ اپLab SetupLab Setup
پچھلی labs والا ASAv۔ 10.1.1.50 (inside) پر syslog server logs receive کرے گا؛ monitoring views کے لیے ASDM access available ہے۔Pichli labs wala ASAv. 10.1.1.50 (inside) par syslog server logs receive karega; monitoring views ke liye ASDM access available hai.ASAv from earlier labs. A syslog server at 10.1.1.50 (inside) will receive logs; ASDM access is available for the monitoring views.
اقداماتStepsSteps
Step 1
Timestamps کے ساتھ logging enable کریں، local buffer کو 1 MB دیں، اور locally warnings اور above (level 4) store کریں۔Timestamps ke sath logging enable karo, local buffer ko 1 MB do, aur locally warnings aur above (level 4) store karo.Enable logging with timestamps, give the local buffer 1 MB, and store warnings and above (level 4) locally.
logging enable logging timestamp logging buffer-size 1048576 logging buffered warnings
Step 2
Inside network پر syslog server کو notifications اور above (level 5) بھیجیں۔Inside network par syslog server ko notifications aur above (level 5) bhejo.Send notifications and above (level 5) to the syslog server on the inside network.
logging trap notifications logging host inside 10.1.1.50
Step 3
Buffered log دیکھیں۔ ہر message میں severity اور ID ہوتی ہے (جیسے %ASA-4-106023) — ID بتاتی ہے exactly کون سا event fire ہوا۔Buffered log dekho. Har message mein severity aur ID hoti hai (jaise %ASA-4-106023) — ID batati hai exactly kaun sa event fire hua.View the buffered log. Each message has a severity and ID (like %ASA-4-106023) — the ID tells you exactly which event fired.
show logging
Step 4
Internet سے DMZ server تک simulated web packet trace کریں۔ ہر phase پڑھیں: کیا ACL pass ہوتا ہے، NAT ہوتا ہے، route ملتا ہے — اور final action ALLOW ہے یا DROP؟Internet se DMZ server tak simulated web packet trace karo. Har phase parho: kya ACL pass hota hai, NAT hota hai, route milta hai — aur final action ALLOW hai ya DROP?Trace a simulated web packet from the internet to the DMZ server. Read each phase: does it pass the ACL, get NATed, find a route — and is the final action ALLOW or DROP?
packet-tracer input outside tcp 203.0.113.50 12345 203.0.113.10 80 detailed
🖱️ ASDM: Monitoring > Properties > Packet Tracer — GUI میں 5-tuple بھریں اور ہر phase visually step کریں۔ASDM: Monitoring > Properties > Packet Tracer — GUI mein 5-tuple bharo aur har phase visually step karo.ASDM: Monitoring > Properties > Packet Tracer — fill the 5-tuple in the GUI and step through each phase visually.
Step 5
Outside interface پر server کی طرف web traffic پر filtered real packet capture لیں، پھر display کریں۔ Captures وہ دکھاتے ہیں جو packet-tracer صرف simulate کرتا ہے۔Outside interface par server ki taraf web traffic par filtered real packet capture lo, phir display karo. Captures woh dikhate hain jo packet-tracer sirf simulate karta hai.Take a real packet capture on the outside interface filtered to web traffic to the server, then display it. Captures show what packet-tracer only simulates.
capture CAP interface outside match tcp host 203.0.113.10 eq www any show capture CAP
Step 6
Capture ہٹائیں اور configuration save کریں۔Capture hatao aur configuration save karo.Remove the capture and save the configuration.
no capture CAP write memory
تصدیقVerifyVerify
`show logging` میں recent warnings نظر آئیں، syslog server کو test messages ملیں، اور DMZ web server کے لیے packet-tracer ALLOW پر ختم ہو جبکہ blocked port reason کے ساتھ DROP پر۔`show logging` mein recent warnings nazar aain, syslog server ko test messages milen, aur DMZ web server ke liye packet-tracer ALLOW par khatam ho jabke blocked port reason ke sath DROP par.`show logging` shows recent warnings, the syslog server receives test messages, and packet-tracer for the DMZ web server ends in ALLOW while a blocked port ends in DROP with a reason.
show logging show run logging
خرابی دور کرناTroubleshootingTroubleshooting
⚠️ Syslog server کو کچھ receive نہیں ہو رہا۔Syslog server ko kuch receive nahi ho raha.The syslog server receives nothing.
✅ Verify کریں `show run logging` میں `logging trap` اور `logging host` دونوں ہیں، confirm کریں ASA سے 10.1.1.50 تک UDP 514 کسی ACL سے blocked نہیں، اور check کریں server پر syslog daemon واقعی listen کر رہا ہے۔Verify karo `show run logging` mein `logging trap` aur `logging host` dono hain, confirm karo ASA se 10.1.1.50 tak UDP 514 kisi ACL se blocked nahi, aur check karo server par syslog daemon waqai listen kar raha hai.Verify `show run logging` has both `logging trap` and `logging host`, confirm UDP 514 from the ASA to 10.1.1.50 isn't blocked by an ACL, and check the syslog daemon is actually listening on the server.
⚠️ packet-tracer DROP کہتا ہے لیکن کیوں، یہ نہیں بتاتا۔packet-tracer DROP kehta hai lekin kyun, ye nahi batata.packet-tracer says DROP but doesn't say why.
✅ `detailed` keyword کے ساتھ دوبارہ چلائیں — یہ ہر phase expand کرتا ہے۔ Dropping phase exact feature کا نام بتاتا ہے (جیسے ACL line یا missing route)؛ اس feature کو fix کریں اور دوبارہ trace کریں۔`detailed` keyword ke sath dobara chalao — ye har phase expand karta hai. Dropping phase exact feature ka naam batata hai (jaise ACL line ya missing route); us feature ko fix karo aur dobara trace karo.Rerun with the `detailed` keyword — it expands every phase. The dropping phase names the exact feature (e.g. an ACL line or a missing route); fix that feature and re-trace.
انٹرویو سوالاتInterview Q&AInterview Q&A
❓ ASA logging levels کیا ہیں اور production میں کون سے use ہوتے ہیں؟ASA logging levels kya hain aur production mein kaun se use hote hain?What are ASA logging levels and which are used in production?
Level 0 emergencies سے 7 debugging تک۔ Production میں typically level 4 (warnings) یا 5 (notifications) پر syslog server کو log ہوتا ہے؛ level 7 debugging log flood کر دیتا ہے اور صرف troubleshooting میں تھوڑی دیر کے لیے use ہوتا ہے۔Level 0 emergencies se 7 debugging tak. Production mein typically level 4 (warnings) ya 5 (notifications) par syslog server ko log hota hai; level 7 debugging log flood kar deta hai aur sirf troubleshooting mein thodi der ke liye use hota hai.Level 0 emergencies through 7 debugging. Production typically logs at level 4 (warnings) or 5 (notifications) to a syslog server; level 7 debugging floods the log and is only used briefly during troubleshooting.
❓ ASA پر packet-tracer command کیا کرتا ہے؟ASA par packet-tracer command kya karta hai?What does the packet-tracer command do on the ASA?
`packet-tracer input <if> <proto> <src-ip> <src-port> <dst-ip> <dst-port>` ASA سے packet simulate کرتا ہے اور ہر phase دکھاتا ہے: ACL check، NAT، route lookup — آخر میں ALLOW یا DROP exact reason کے ساتھ۔ ASDM میں same tool Monitoring کے نیچے ہے۔`packet-tracer input <if> <proto> <src-ip> <src-port> <dst-ip> <dst-port>` ASA se packet simulate karta hai aur har phase dikhata hai: ACL check, NAT, route lookup — aakhir mein ALLOW ya DROP exact reason ke sath. ASDM mein same tool Monitoring ke neeche hai.`packet-tracer input <if> <proto> <src-ip> <src-port> <dst-ip> <dst-port>` simulates a packet through the ASA and shows each phase: ACL check, NAT, route lookup — ending in ALLOW or DROP with the exact reason. ASDM has the same tool under Monitoring.