Syslog across VPN?

Since the ASA logging host command want you to define the interface that points toward the syslog server (which in your case is the outside interface) I do not think this will work. It will want to use the ip address of the outside interface and this is not part of the tunnel, so no traffic.

 

Shitty solution #1: NAT rule on outside interface on the other end for syslog packets to be forwarded to the syslog server (means the syslog packets go in cleartext on the internet).

 

Shitty solution #2: Install and configure a forwarding syslog server on the inside interface. Let this server forward the ASA syslog packets over the tunnel to the syslog server on the other end.

/r/Cisco Thread