I have a quick question regarding logging on a Pix 535.

We're currently getting a lot of CERT notifications for spammers
operating within our network - mainly just students with 0wned machines,
but we're looking into ways to automate the procedure slightly.

Anyway, what I'm looking to do, and what I need help with.... I want to
know if it's possible to log all outbound port 25 connection attempts,
EXCEPT those that come from our authorised MX's and mail servers. AND I
would like to be able to do this in addition to the normal logging that
takes place.

So, is it possible?

Any thoughts and guidance you can provide are very much appreciated.


James Burns

