[fw-wiz] RE: Router Internet Monitoring

From: Dave (update_at_dsrtech.com)
Date: 09/05/03

  • Next message: Jeff B: "[fw-wiz] RE: firewall-wizards digest, Vol 1 #1077 - 2 msgs"
    To: George Peek <GKPeek@AllstateTicketing.com>
    Date: Thu, 04 Sep 2003 18:57:30 -0400
    
    

    George,

    You can enable debugging logging to syslog and then exclude which
    messages you will not want to see with the command
    "no logging message <msg number>"
    example "no logging message 305012"

    Then you can filter your syslog with grep by interface.

    Note this will show all url traffic to all interfaces/dmz(s) and yes
    this will load up your syslog file.

    I would recommend a tool called "IPAudit-Web". This makes an excellent
    tracking tool. http://ipaudit.sourceforge.net/ipaudit-web/

    I understand you don't want to capture all traffic but this tool is an
    excellent resource at my shop and you could span a switch port off the
    dmz you wished to monitor.

    Good luck to you.

    Dave

    On Thu, 2003-09-04 at 15:21, George Peek wrote:
    > Problem with Pix is it is logging literally everything, hence we have
    > multiple DMZs.. for frame, dial-up, internet, internal, etc. I have not
    > fully explored filtering, we use Kiwi Syslog Daemon for logging but the file
    > grows extremely huge. In the future, SQL solution (which it supports) will
    > be implemented but for now I need something live to monitor.
    >
    > Can you use the Cisco Pix Device Manager to filter the log?
    >
    > -----Original Message-----
    > From: rogue [mailto:rogue@nocdemon.net]
    > Sent: Thursday, September 04, 2003 9:29 AM
    > To: George Peek
    > Cc: 'security-basics@securityfocus.com'; 'owen@delong.com';
    > 'firewall-wizards@honor.icsalabs.com'
    > Subject: Re: Router Internet Monitoring
    >
    >
    >
    > if you tell your PIX to log to a syslog server and ramp up the PIX logging
    > to informational youll see every URL connection made from withinyour
    > network.
    >
    > -rogue
    >
    > On Wed, 3 Sep 2003, George Peek wrote:
    >
    > > This may be a bit offtopic, if so please excuse me. I am looking for a
    > > solution to monitor the live traffic (i.e. incoming/outgoing traffic,
    > incl.
    > > able to determine what url the user is going to) on our Cisco 2620.
    > Freeware
    > > would be great, linux solution is ok. I don't want to use a network
    > capture
    > > utility such as sniffer, fluke or iris. Pix has the device manager which
    > > comes in handy. I can enable logging via SNMP, but it is text based, a GUI
    > > utility that will sort that information would be very cool.
    > >
    > > Thank You,
    > > George Peek
    > >
    > >
    > ---------------------------------------------------------------------------
    > > Attend Black Hat Briefings & Training Federal, September 29-30 (Training),
    > > October 1-2 (Briefings) in Tysons Corner, VA; the world's premier
    > > technical IT security event. Modeled after the famous Black Hat event in
    > > Las Vegas! 6 tracks, 12 training sessions, top speakers and sponsors.
    > > Symantec is the Diamond sponsor. Early-bird registration ends September
    > 6.Visit us: www.blackhat.com
    > >
    > ----------------------------------------------------------------------------
    > >

    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: Jeff B: "[fw-wiz] RE: firewall-wizards digest, Vol 1 #1077 - 2 msgs"

    Relevant Pages

    • Re: Pix Debug Commands
      ... I am trying to figure out why my pix is blocking ICMP ... as would pushing your logging level up to 6 and ... syslog server. ...
      (comp.dcom.sys.cisco)
    • RE: where should I start? help!
      ... you could also use the syslog feature in any *NIX system ... Plus there are tons of log analyzers for ... from your PIX to the listening device. ... and you can have more than one logging host system if need be. ...
      (Security-Basics)
    • Re: Logging and Auditing of a HP-UX box
      ... Would members of this group kindly tell me the auditing and logging ... You can expect the syslog system to be always enabled, ... All syslog messages consist of a level identifier, ... commands to control the audit log system from the command ...
      (comp.security.unix)
    • RE: [fw-wiz] pix 501 logging question
      ... it's a deny, right?), which would lead to more syslog data from persistent ... log level for access-list logging is 6, but if you can see one you should ... You don't need to force the PIX to log these denials, ... access-list inbound permitted tcp outside/205.206.xxx.xxx-> ...
      (Firewall-Wizards)
    • Re: Logging and Auditing of a HP-UX box
      ... Would members of this group kindly tell me the auditing and logging ... You can expect the syslog system to be always enabled, ... All syslog messages consist of a level identifier, ... commands to control the audit log system from the command ...
      (comp.security.unix)