<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: fmc syslog in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fmc-syslog/m-p/4748651#M1096432</link>
    <description>&lt;P&gt;what NAC here ?&lt;/P&gt;
&lt;P&gt;how is your syslog config TCP or UDP ?&lt;/P&gt;</description>
    <pubDate>Tue, 03 Jan 2023 18:15:06 GMT</pubDate>
    <dc:creator>balaji.bandi</dc:creator>
    <dc:date>2023-01-03T18:15:06Z</dc:date>
    <item>
      <title>fmc syslog</title>
      <link>https://community.cisco.com/t5/network-security/fmc-syslog/m-p/4748625#M1096430</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;i have ftd with fmc running 7.0.1, i have configured the syslog server to send the remote vpn syslogs to a NAC for posture and compliance check. Now the logs are showing up in the NAC, but, in encrypted format not in cleartext.&lt;/P&gt;&lt;P&gt;Kind assistance is required, if anybody knows how to send syslogs in cleartext to external syslog server from fmc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jan 2023 17:32:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-syslog/m-p/4748625#M1096430</guid>
      <dc:creator>shaikh.zaid22</dc:creator>
      <dc:date>2023-01-03T17:32:38Z</dc:date>
    </item>
    <item>
      <title>Re: fmc syslog</title>
      <link>https://community.cisco.com/t5/network-security/fmc-syslog/m-p/4748650#M1096431</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- Are you sure this is not related to the NAC handling of the logs ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jan 2023 18:14:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-syslog/m-p/4748650#M1096431</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2023-01-03T18:14:01Z</dc:date>
    </item>
    <item>
      <title>Re: fmc syslog</title>
      <link>https://community.cisco.com/t5/network-security/fmc-syslog/m-p/4748651#M1096432</link>
      <description>&lt;P&gt;what NAC here ?&lt;/P&gt;
&lt;P&gt;how is your syslog config TCP or UDP ?&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jan 2023 18:15:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-syslog/m-p/4748651#M1096432</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2023-01-03T18:15:06Z</dc:date>
    </item>
    <item>
      <title>Re: fmc syslog</title>
      <link>https://community.cisco.com/t5/network-security/fmc-syslog/m-p/4748658#M1096433</link>
      <description>&lt;P&gt;Hi marce and balaji,&lt;/P&gt;&lt;P&gt;Yes it is a forescout NAC, we are configuring for VPN events and then apply compliance policy. However, the logs are not readable. I was wondering whether it is the job of the forescout parser or fmc is sending syslogs in unreadable format.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jan 2023 18:28:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-syslog/m-p/4748658#M1096433</guid>
      <dc:creator>shaikh.zaid22</dc:creator>
      <dc:date>2023-01-03T18:28:58Z</dc:date>
    </item>
    <item>
      <title>Re: fmc syslog</title>
      <link>https://community.cisco.com/t5/network-security/fmc-syslog/m-p/4748660#M1096434</link>
      <description>&lt;P&gt;We are sending UDP 514 ports.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jan 2023 18:29:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-syslog/m-p/4748660#M1096434</guid>
      <dc:creator>shaikh.zaid22</dc:creator>
      <dc:date>2023-01-03T18:29:46Z</dc:date>
    </item>
    <item>
      <title>Re: fmc syslog</title>
      <link>https://community.cisco.com/t5/network-security/fmc-syslog/m-p/4749294#M1096459</link>
      <description>&lt;P&gt;Syslog from the FMC should not be encrypted, Are you sure you are not using eStreamer?&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jan 2023 20:40:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-syslog/m-p/4749294#M1096459</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2023-01-04T20:40:55Z</dc:date>
    </item>
    <item>
      <title>Re: fmc syslog</title>
      <link>https://community.cisco.com/t5/network-security/fmc-syslog/m-p/4749316#M1096460</link>
      <description>&lt;P&gt;personally, never seen this issue before until we missing something here?&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jan 2023 21:24:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-syslog/m-p/4749316#M1096460</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2023-01-04T21:24:16Z</dc:date>
    </item>
    <item>
      <title>Re: fmc syslog</title>
      <link>https://community.cisco.com/t5/network-security/fmc-syslog/m-p/4749400#M1096468</link>
      <description>&lt;P&gt;We have Forescout NAC, wherein we are capturing VPN logs, which is not showing in plaintext.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jan 2023 04:11:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-syslog/m-p/4749400#M1096468</guid>
      <dc:creator>shaikh.zaid22</dc:creator>
      <dc:date>2023-01-05T04:11:10Z</dc:date>
    </item>
    <item>
      <title>Re: fmc syslog</title>
      <link>https://community.cisco.com/t5/network-security/fmc-syslog/m-p/4749468#M1096472</link>
      <description>&lt;P&gt;That is a bit odd, you should be seeing the permit / deny logs received on the "inside" interfaces.&amp;nbsp; Do you have sysopt connection permit-vpn enabled?&amp;nbsp; If you have this enabled you could try disabling it, but then be aware that you need to configure access rules on the outside interface for the VPN traffic, and then enable syslog for those rules.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jan 2023 08:24:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-syslog/m-p/4749468#M1096472</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2023-01-05T08:24:58Z</dc:date>
    </item>
  </channel>
</rss>

