<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Syslog in FMC in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/syslog-in-fmc/m-p/4825766#M1100062</link>
    <description>&lt;P&gt;Sure will provide the log.&lt;/P&gt;&lt;P&gt;No FW in between. UDP port 514 is open and working for other traffic. Whenever ravpn client connects or disconnects this info is not coming-in to the syslog.&lt;/P&gt;</description>
    <pubDate>Mon, 01 May 2023 18:09:09 GMT</pubDate>
    <dc:creator>shaikh.zaid22</dc:creator>
    <dc:date>2023-05-01T18:09:09Z</dc:date>
    <item>
      <title>Syslog in FMC</title>
      <link>https://community.cisco.com/t5/network-security/syslog-in-fmc/m-p/4823029#M1099958</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;i am having ftd's managed via fmc running ver7.0.1 and the FMC is configured too forward vpn logs to syslog server which is a forescout NAC appliance.&lt;/P&gt;&lt;P&gt;Since we are not getting any logs in the destination, i want to know how to verify the vpn logs are being sent by FMC managment interface ip address or the active FTD device??&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Apr 2023 13:18:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/syslog-in-fmc/m-p/4823029#M1099958</guid>
      <dc:creator>shaikh.zaid22</dc:creator>
      <dc:date>2023-04-27T13:18:58Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog in FMC</title>
      <link>https://community.cisco.com/t5/network-security/syslog-in-fmc/m-p/4823032#M1099959</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/58993"&gt;@shaikh.zaid22&lt;/a&gt; the syslogs are sent from the FTD to the configured syslog server.&lt;/P&gt;
&lt;P&gt;If you are not receiving the logs run a packet capture to confirm the logs are being transmitted and double check the configuration.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Apr 2023 13:29:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/syslog-in-fmc/m-p/4823032#M1099959</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2023-04-27T13:29:10Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog in FMC</title>
      <link>https://community.cisco.com/t5/network-security/syslog-in-fmc/m-p/4823038#M1099960</link>
      <description>&lt;P&gt;Can I know ftd&amp;nbsp; platform you have ?&lt;/P&gt;</description>
      <pubDate>Thu, 27 Apr 2023 13:39:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/syslog-in-fmc/m-p/4823038#M1099960</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-04-27T13:39:10Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog in FMC</title>
      <link>https://community.cisco.com/t5/network-security/syslog-in-fmc/m-p/4823214#M1099965</link>
      <description>&lt;P&gt;Adding to what &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt; said, the syslog message should originate from the management address of the active FTD (assuming you have it setup properly in the platform settings).&lt;/P&gt;</description>
      <pubDate>Thu, 27 Apr 2023 16:47:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/syslog-in-fmc/m-p/4823214#M1099965</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2023-04-27T16:47:38Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog in FMC</title>
      <link>https://community.cisco.com/t5/network-security/syslog-in-fmc/m-p/4823319#M1099970</link>
      <description>&lt;P&gt;Rob can u share the packet capture cpmmand.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Apr 2023 19:28:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/syslog-in-fmc/m-p/4823319#M1099970</guid>
      <dc:creator>shaikh.zaid22</dc:creator>
      <dc:date>2023-04-27T19:28:22Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog in FMC</title>
      <link>https://community.cisco.com/t5/network-security/syslog-in-fmc/m-p/4823320#M1099971</link>
      <description>&lt;P&gt;FTDs model is 2110&lt;/P&gt;</description>
      <pubDate>Thu, 27 Apr 2023 19:28:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/syslog-in-fmc/m-p/4823320#M1099971</guid>
      <dc:creator>shaikh.zaid22</dc:creator>
      <dc:date>2023-04-27T19:28:46Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog in FMC</title>
      <link>https://community.cisco.com/t5/network-security/syslog-in-fmc/m-p/4823322#M1099972</link>
      <description>&lt;P&gt;Thanks Marvin&lt;/P&gt;&lt;P&gt;I have configured specific ravpn logs only to be forwarded to syslog server.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Apr 2023 19:29:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/syslog-in-fmc/m-p/4823322#M1099972</guid>
      <dc:creator>shaikh.zaid22</dc:creator>
      <dc:date>2023-04-27T19:29:41Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog in FMC</title>
      <link>https://community.cisco.com/t5/network-security/syslog-in-fmc/m-p/4825494#M1100042</link>
      <description>&lt;P&gt;Hi rob,&lt;/P&gt;&lt;P&gt;Can u pls provide the command or the doc pls&lt;/P&gt;</description>
      <pubDate>Mon, 01 May 2023 13:03:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/syslog-in-fmc/m-p/4825494#M1100042</guid>
      <dc:creator>shaikh.zaid22</dc:creator>
      <dc:date>2023-05-01T13:03:30Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog in FMC</title>
      <link>https://community.cisco.com/t5/network-security/syslog-in-fmc/m-p/4825522#M1100046</link>
      <description>&lt;P&gt;Access to mgnt interface of ftd&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Then&amp;nbsp;&lt;/P&gt;
&lt;P&gt;System support diagnostics cli&lt;/P&gt;
&lt;P&gt;Then&lt;/P&gt;
&lt;P&gt;Ping to syslog server &amp;lt;&amp;lt;- are ping success ?&lt;/P&gt;</description>
      <pubDate>Mon, 01 May 2023 13:50:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/syslog-in-fmc/m-p/4825522#M1100046</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-05-01T13:50:35Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog in FMC</title>
      <link>https://community.cisco.com/t5/network-security/syslog-in-fmc/m-p/4825744#M1100058</link>
      <description>&lt;P&gt;yes its pingable from ftd.&lt;/P&gt;</description>
      <pubDate>Mon, 01 May 2023 17:35:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/syslog-in-fmc/m-p/4825744#M1100058</guid>
      <dc:creator>shaikh.zaid22</dc:creator>
      <dc:date>2023-05-01T17:35:04Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog in FMC</title>
      <link>https://community.cisco.com/t5/network-security/syslog-in-fmc/m-p/4825748#M1100060</link>
      <description>&lt;PRE&gt;firepower# sh run logging &amp;lt;&amp;lt;- can I see this
&lt;/PRE&gt;
&lt;P&gt;few more tips to check&amp;nbsp;&lt;BR /&gt;are there any&amp;nbsp; other FW between the Syslog and FTD ? are log UDP port is Open ? are the Syslog listen to UDP or TCP port ?&lt;BR /&gt;what is accept log format by Syslog?&lt;/P&gt;</description>
      <pubDate>Mon, 01 May 2023 18:00:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/syslog-in-fmc/m-p/4825748#M1100060</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-05-01T18:00:04Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog in FMC</title>
      <link>https://community.cisco.com/t5/network-security/syslog-in-fmc/m-p/4825766#M1100062</link>
      <description>&lt;P&gt;Sure will provide the log.&lt;/P&gt;&lt;P&gt;No FW in between. UDP port 514 is open and working for other traffic. Whenever ravpn client connects or disconnects this info is not coming-in to the syslog.&lt;/P&gt;</description>
      <pubDate>Mon, 01 May 2023 18:09:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/syslog-in-fmc/m-p/4825766#M1100062</guid>
      <dc:creator>shaikh.zaid22</dc:creator>
      <dc:date>2023-05-01T18:09:09Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog in FMC</title>
      <link>https://community.cisco.com/t5/network-security/syslog-in-fmc/m-p/4825782#M1100063</link>
      <description>&lt;P&gt;&lt;SPAN&gt;if traffic log is send and only RAVPN is not what is level of logging you use ?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Any VPN syslogs that are displayed have a default severity level ‘&lt;STRONG&gt;ERROR&lt;/STRONG&gt;’ or higher (unless changed). VPN logging is managed through&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="ph"&gt;FTD&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;platform settings.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 01 May 2023 18:15:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/syslog-in-fmc/m-p/4825782#M1100063</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-05-01T18:15:39Z</dc:date>
    </item>
  </channel>
</rss>

