<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FTD Secure Syslog in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ftd-secure-syslog/m-p/4897262#M1103165</link>
    <description>&lt;P&gt;Thanks, I read that as well, but as you mention its vague around the certificate as there is a need to create certificate enrolment objects as part of the identity certificate.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 01 Aug 2023 22:44:57 GMT</pubDate>
    <dc:creator>goudier2001</dc:creator>
    <dc:date>2023-08-01T22:44:57Z</dc:date>
    <item>
      <title>FTD Secure Syslog</title>
      <link>https://community.cisco.com/t5/network-security/ftd-secure-syslog/m-p/4897015#M1103145</link>
      <description>&lt;P&gt;Can anyone provide documentation on configuring Secure Syslog from FTD's.&lt;/P&gt;&lt;P&gt;Documentation is limited from Cisco.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Aug 2023 14:40:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-secure-syslog/m-p/4897015#M1103145</guid>
      <dc:creator>goudier2001</dc:creator>
      <dc:date>2023-08-01T14:40:43Z</dc:date>
    </item>
    <item>
      <title>Re: FTD Secure Syslog</title>
      <link>https://community.cisco.com/t5/network-security/ftd-secure-syslog/m-p/4897066#M1103146</link>
      <description>&lt;P&gt;You meaning config syslog for FTD by FDM or FMC ?&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/200479-Configure-Logging-on-FTD-via-FMC.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/200479-Configure-Logging-on-FTD-via-FMC.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Aug 2023 15:59:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-secure-syslog/m-p/4897066#M1103146</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-08-01T15:59:28Z</dc:date>
    </item>
    <item>
      <title>Re: FTD Secure Syslog</title>
      <link>https://community.cisco.com/t5/network-security/ftd-secure-syslog/m-p/4897141#M1103153</link>
      <description>&lt;P&gt;I mean configuring secure Syslog FTD by FMC&lt;/P&gt;</description>
      <pubDate>Tue, 01 Aug 2023 17:49:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-secure-syslog/m-p/4897141#M1103153</guid>
      <dc:creator>goudier2001</dc:creator>
      <dc:date>2023-08-01T17:49:15Z</dc:date>
    </item>
    <item>
      <title>Re: FTD Secure Syslog</title>
      <link>https://community.cisco.com/t5/network-security/ftd-secure-syslog/m-p/4897145#M1103154</link>
      <description>&lt;P&gt;Then check link I share above&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Aug 2023 17:58:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-secure-syslog/m-p/4897145#M1103154</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-08-01T17:58:10Z</dc:date>
    </item>
    <item>
      <title>Re: FTD Secure Syslog</title>
      <link>https://community.cisco.com/t5/network-security/ftd-secure-syslog/m-p/4897152#M1103155</link>
      <description>&lt;P&gt;Thanks, I've seen the document you provided, but its doesn't cover off the certificate side of the secure syslog element for FTD which is what I'm after if you could help?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Aug 2023 18:10:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-secure-syslog/m-p/4897152#M1103155</guid>
      <dc:creator>goudier2001</dc:creator>
      <dc:date>2023-08-01T18:10:24Z</dc:date>
    </item>
    <item>
      <title>Re: FTD Secure Syslog</title>
      <link>https://community.cisco.com/t5/network-security/ftd-secure-syslog/m-p/4897260#M1103164</link>
      <description>&lt;P&gt;There's a bit better description, although not superb, in the Platform Settings part of the documentation:&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/720/management-center-device-config-72/interfaces-settings-platform.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/720/management-center-device-config-72/interfaces-settings-platform.html&lt;/A&gt;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;&lt;BR /&gt;
&lt;P&gt;"Check the Enable Secure Syslog check box to encrypt the connection between the device and server using SSL/TLS over TCP.&lt;/P&gt;
&lt;P&gt;Note You must select TCP as the protocol to use this option. You must also upload the certificate required to communicate with the syslog server on the Devices &amp;gt; Certificates page. Finally, upload the certificate from the threat defense device to the syslog server to complete the secure relationship and allow it to decrypt the traffic. The Enable Secure Syslog option is not supported on the device Management interface. "&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P class="ph cmd"&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;SECTION class="itemgroup info"&gt;&lt;/SECTION&gt;</description>
      <pubDate>Tue, 01 Aug 2023 22:39:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-secure-syslog/m-p/4897260#M1103164</guid>
      <dc:creator>Jonatan Jonasson</dc:creator>
      <dc:date>2023-08-01T22:39:23Z</dc:date>
    </item>
    <item>
      <title>Re: FTD Secure Syslog</title>
      <link>https://community.cisco.com/t5/network-security/ftd-secure-syslog/m-p/4897262#M1103165</link>
      <description>&lt;P&gt;Thanks, I read that as well, but as you mention its vague around the certificate as there is a need to create certificate enrolment objects as part of the identity certificate.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Aug 2023 22:44:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-secure-syslog/m-p/4897262#M1103165</guid>
      <dc:creator>goudier2001</dc:creator>
      <dc:date>2023-08-01T22:44:57Z</dc:date>
    </item>
    <item>
      <title>Re: FTD Secure Syslog</title>
      <link>https://community.cisco.com/t5/network-security/ftd-secure-syslog/m-p/4897268#M1103166</link>
      <description>&lt;P&gt;Hi again, I tested this in my lab using FMC and rsyslog, and to share with you my results.&lt;/P&gt;
&lt;P&gt;The syslog server has it's certificate and private key, and most servers only support one certificate per instance.&lt;BR /&gt;My rsyslog setup was based on the following tutorial:&amp;nbsp;&lt;A href="https://www.rsyslog.com/doc/master/tutorials/tls.html" target="_blank"&gt;https://www.rsyslog.com/doc/master/tutorials/tls.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;The certificate I had on my syslog server was signed by an intermediate cert which in turn is signed by a root ca.&lt;/P&gt;
&lt;P&gt;I started by only adding the public key of my syslog certificate to the managed device via FMC (device-&amp;gt;certificates). I noticed that the device tried to communicate with my syslog but I did not get anything in my logs.&lt;BR /&gt;I then added the intermediate certificate to the device, and now I'm logs successfully.&lt;BR /&gt;I then removed the syslog identify certificate from the FMC/device, and syslog still works.&lt;/P&gt;
&lt;P&gt;While I haven't tested with self-signed certificates, my conclusion is:&lt;/P&gt;
&lt;P&gt;You only need to add the signing certificate of the syslog certificate (ie the intermediate, or root ca depending on your setup) to the device managed by FMC, and then check the "enable secure syslog", and since the device trusts the syslog issuer, TLS encrypted syslogs flow.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Aug 2023 23:26:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-secure-syslog/m-p/4897268#M1103166</guid>
      <dc:creator>Jonatan Jonasson</dc:creator>
      <dc:date>2023-08-01T23:26:36Z</dc:date>
    </item>
    <item>
      <title>Re: FTD Secure Syslog</title>
      <link>https://community.cisco.com/t5/network-security/ftd-secure-syslog/m-p/4897270#M1103168</link>
      <description>&lt;P&gt;to clarify with demo data:&lt;BR /&gt;My root CA:&amp;nbsp;CN = Natti Root CA&lt;BR /&gt;My intermediate CA:&amp;nbsp;CN = Natti Intermediate CA&amp;nbsp; (issued by Natti root CA)&lt;BR /&gt;My rsyslog certificate:&amp;nbsp;CN = rsyslog (issued by Natti Intermediate CA)&lt;/P&gt;
&lt;P&gt;I installed the "Natti Intermediate CA" (pubkey only) certificate on the managed FTD device via FMC -&amp;gt; Devices -&amp;gt; Certificates&lt;BR /&gt;And then added the syslog server with the "&lt;SPAN&gt;Enable secure syslog" checked.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Aug 2023 23:33:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-secure-syslog/m-p/4897270#M1103168</guid>
      <dc:creator>Jonatan Jonasson</dc:creator>
      <dc:date>2023-08-01T23:33:19Z</dc:date>
    </item>
  </channel>
</rss>

