[fw-wiz] Re: PIX syslog WAS: (no subject)

From: Carson Gaspar (carson_at_taltos.org)
Date: 03/24/04

  • Next message: Robert L. Wanamaker: "[fw-wiz] IP migration on "hub" VPN terminus [long]"
    To: firewall-wizards@honor.icsalabs.com
    Date: Tue, 23 Mar 2004 18:16:49 -0500

    --On Tuesday, March 23, 2004 08:48:56 -0500 "Paul D. Robertson"
    <paul@compuwar.net> wrote:

    > Any syslog server will work, it's a standard protocol. I prefer
    > minirsyslogd on Linux boxes.

    Not _quite_ true. Cisco supports a proprietary syslog over TCP
    implementation on the PIX (as well as standard, lossy, UDP syslog).
    syslog-ng (under unix-like OSes) supports the TCP format. According to
    google, so does the Kiwi syslog daemon for Win32 (recommended by several
    other people on this list), as well as the Cisco PIX Firewall Syslog Server

    firewall-wizards mailing list

  • Next message: Robert L. Wanamaker: "[fw-wiz] IP migration on "hub" VPN terminus [long]"

    Relevant Pages

    • Re: [fw-wiz] Syslog set up
      ... In PIX v6.3, Cisco added the ability to filter out specific log messages ... Syslog by access control list entry ...
    • Re: Syslog over SSH
      ... Subject: Syslog over SSH ... > UDP/514 to TCP using netcat then pass it to another machine ...
    • Re: Easy newbie Question
      ... "cmd" was not in the command ref guides. ... But it's only syslog when using UDP. ... TCP is remote-cmd.. ...
    • RE: where should I start? help!
      ... you could also use the syslog feature in any *NIX system ... Plus there are tons of log analyzers for ... from your PIX to the listening device. ... and you can have more than one logging host system if need be. ...
    • Re: [fw-wiz] Syslog montioring and usage.
      ... While the PIX doesn't have a "port scan" syslog message it does log what it ... source IP address of the packets, as well as the protocol and port the ...