Enabling and Disabling Logging of Denied Traffic.

A knowledge base article about Enabling and Disabling Logging of Denied Traffic. provided by the UC Berkeley IT Service Hub - Knowledge Portal

When troubleshooting issues with the firewalls including why connections were not allowed by a rule, it is sometimes necessary to enable logging of denied traffic. The steps necessary to configure logging of denied traffic are as follows:

  1. Log into https://panorama.net.berkeley.edu using single sign-on
  2. From the tabs at the top of the window chose "Policies"
    The Policy Tab in Panorama
  3. Under "Security" in the left pane choose “Default Rules”
  4. Highlight the "interzone-default" rule
  5. Select "Override" at the bottom of the screen
  6. When the "Security Policy Rule - predefined" window appears click the "Actions" tab
  7. Select "Log at Session End"
  8. Change Log Forwarding to "default"
  9. Press the "OK" button
  10. "Commit and Push" the change to the firewalls

At this point, any traffic that is stopped by the firewall, because their is not an allow rule, will be logged to the "Traffic" logs under the "Monitor" tab in Panorama. To undo this setting when you are done:

  1. Log into https://panorama.net.berkeley.edu using single sign-on
  2. From the tabs at the top of the window chose "Policies"
  3. Under "Security" in the left pane choose “Default Rules”
  4. Highlight the "interzone-default" rule.
  5. Select "Revert" at the bottom of the screen
  6. When prompted to confirm the revert click "Yes" Button
  7. Commit and Push" the change to the firewalls