Cisco ip inspect log drop packets

ip inspect log drop-pkt

To log all packets dropped by the firewall, use the
ip inspect log drop-pkt
command in global configuration mode.
To return to the default state, use the no form of this command.

ip inspect log drop-pkt
no ip inspect log drop-pkt