1-3
Cisco ASA Series CLI Configuration Guide
Chapter 1 Configuring NetFlow Secure Event Logging (NSEL)
Information About NSEL
Note
When NSEL and syslog messages are both enabled, there is no guarantee of chronological ordering
between the two logging types.
Using NSEL in Clustering
Each ASA establishes its own connection to the collector(s) using its unit local IP address. The fields in
the header of the export packet include the system up time, UNIX time (synchronized across the cluster),
and sequence number. These fields are all local to an individual ASA. The NSEL collector uses the
combination of the source port of the packet to separate different exporters.
Each ASA manages and advertises its template independently. Because the ASA supports in-cluster
upgrades, different units may run different image versions at a certain point in time. As a result, the
template that each ASA supports may be different.
Note
Clustering is available on the ASA 5580 and 5585-X only. For more information about clustering, see
Chapter 1, “Configuring a Cluster of ASAs.”
Table 1-1
Syslog Messages and Equivalent NSEL Events
Syslog Message
Description
NSEL Event ID
NSEL Extended Event ID
106100
Generated whenever an ACL is
encountered.
1—Flow was created (if the
ACL allowed the flow).
3—Flow was denied (if the
ACL denied the flow).
0—If the ACL allowed the flow.
1001—Flow was denied by the
ingress ACL.
1002—Flow was denied by the
egress ACL.
106015
A TCP flow was denied because
the first packet was not a SYN
packet.
3—Flow was denied.
1004—Flow was denied because
the first packet was not a TCP
SYN packet.
106023
When a flow was denied by an
ACL attached to an interface
through the
access-group
command.
3—Flow was denied.
1001—Flow was denied by the
ingress ACL.
1002—Flow was denied by the
egress ACL.
302013, 302015,
302017, 302020
TCP, UDP, GRE, and ICMP
connection creation.
1—Flow was created.
0—Ignore.
302014, 302016,
302018, 302021
TCP, UDP, GRE, and ICMP
connection teardown.
2—Flow was deleted.
0—Ignore.
> 2000—Flow was torn down.
313001
An ICMP packet to the device
was denied.
3—Flow was denied.
1003—To-the-box flow was
denied because of configuration.
313008
An ICMP v6 packet to the device
was denied.
3—Flow was denied.
1003—To-the-box flow was
denied because of configuration.
710003
An attempt to connect to the
device interface was denied.
3—Flow was denied.
1003—To-the-box flow was
denied because of configuration.
Summary of Contents for 5505 - ASA Firewall Edition Bundle
Page 28: ...Glossary GL 24 Cisco ASA Series CLI Configuration Guide ...
Page 61: ...P A R T 1 Getting Started with the ASA ...
Page 62: ......
Page 219: ...P A R T 2 Configuring High Availability and Scalability ...
Page 220: ......
Page 403: ...P A R T 2 Configuring Interfaces ...
Page 404: ......
Page 499: ...P A R T 2 Configuring Basic Settings ...
Page 500: ......
Page 533: ...P A R T 2 Configuring Objects and Access Lists ...
Page 534: ......
Page 601: ...P A R T 2 Configuring IP Routing ...
Page 602: ......
Page 745: ...P A R T 2 Configuring Network Address Translation ...
Page 746: ......
Page 845: ...P A R T 2 Configuring AAA Servers and the Local Database ...
Page 846: ......
Page 981: ...P A R T 2 Configuring Access Control ...
Page 982: ......
Page 1061: ...P A R T 2 Configuring Service Policies Using the Modular Policy Framework ...
Page 1062: ......
Page 1093: ...P A R T 2 Configuring Application Inspection ...
Page 1094: ......
Page 1191: ...P A R T 2 Configuring Unified Communications ...
Page 1192: ......
Page 1333: ...P A R T 2 Configuring Connection Settings and QoS ...
Page 1334: ......
Page 1379: ...P A R T 2 Configuring Advanced Network Protection ...
Page 1380: ......
Page 1475: ...P A R T 2 Configuring Modules ...
Page 1476: ......
Page 1549: ...P A R T 2 Configuring VPN ...
Page 1550: ......
Page 1965: ...P A R T 2 Configuring Logging SNMP and Smart Call Home ...
Page 1966: ......
Page 2059: ...P A R T 2 System Administration ...
Page 2060: ......
Page 2098: ...1 8 Cisco ASA Series CLI Configuration Guide Chapter 1 Troubleshooting Viewing the Coredump ...
Page 2099: ...P A R T 2 Reference ...
Page 2100: ......