Re: [fw-wiz] syslog and network management



Nad,

Depending on the size of the network and the logging level used, a central
syslog can be a very busy server. I wouldn't add Cisco Works (which is
another resource hog) on the same machine, as it could lead on syslog
message loss under heavy traffic conditions. You should check the
documentation of your syslog server on how to dimension the machine running
it, specially if it will be logging to a SQL database

Regards,

Alejandro


----- Original Message -----
From: "shadow floating" <nadengine@xxxxxxxxxxxxxx>
To: "Firewall Wizards Security Mailing List"
<firewall-wizards@xxxxxxxxxxxxxxxxxxxxx>
Sent: Tuesday, February 19, 2008 6:51 PM
Subject: Re: [fw-wiz] syslog and network management


thanks alot patrick, i was not actually asking about the centralized
log server issue as i believe in it...but is it appropriate to add
firewall and router management applications to be installed onto that
server , like ciscoworks and the like?..or it's better to add another
separate management machine in addition to the syslog machine from the
security point of view

thanks alot

Nad


_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxxxxx
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards



Relevant Pages

  • Re: Need to implemet Syslog server
    ... >On my network I need to implement a Syslog server ... Pretty much everything but Windows will ... likely talk to syslog if told to, ... A great many other managed network devices support syslogging, ...
    (Security-Basics)
  • [HPADM] SUMMARY: syslog redirection
    ... server is down, entries will be lost. ... Syslog sends over UDP on a "broadcast and forget" concept. ... information that is subject to United States laws and regulations. ... I'm being asked to route syslog messages to a central server. ...
    (HP-UX-Admin)
  • Re: How to allow port 514?
    ... a packet filter allows traffic into the server itself. ... If you want to run your syslog on the server you would use a packet filter. ... In ISA Policy Elements, right click Protocol Definitions, ... in Publishing, right click Server ...
    (microsoft.public.windows.server.sbs)
  • RE: Syslog Server on Debian Etch
    ... Syslog was working fine on the clients, I had it installed to a diff ... Is anyone else monitoring Juniper Netscreen firewalls? ... Syslog Server on Debian Etch ...
    (Debian-User)
  • SUMMARY: forwarded syslog messages are missing originating hostname
    ... I am running Solaris 9 with the latest_recommended. ... to send their syslog messages to a central server, ... as a relay server to forward all syslog messages to a third server. ... originating servers hostname and state that they are only from the relay ...
    (SunManagers)