<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: BGP Syslog messages on FTD in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/bgp-syslog-messages-on-ftd/m-p/5142810#M1114162</link>
    <description>&lt;P&gt;found this entry in another syslog&amp;nbsp; (XDR), it would appear that inbound traffic from the peer is dropped by the firewall??&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="atsukane_2-1720610949022.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/223072i608252010B824C77/image-size/medium?v=v2&amp;amp;px=400" role="button" title="atsukane_2-1720610949022.png" alt="atsukane_2-1720610949022.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 10 Jul 2024 11:29:35 GMT</pubDate>
    <dc:creator>atsukane</dc:creator>
    <dc:date>2024-07-10T11:29:35Z</dc:date>
    <item>
      <title>BGP Syslog messages on FTD</title>
      <link>https://community.cisco.com/t5/network-security/bgp-syslog-messages-on-ftd/m-p/5142748#M1114157</link>
      <description>&lt;P&gt;Hi team,&lt;/P&gt;&lt;P&gt;FMCv 7.4.1&amp;nbsp; and FPR2140 running 7.2.7&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are seeing an issue with BGP failing on FTD 2140 with AWS.&lt;/P&gt;&lt;P&gt;Not established exactly when this has started, potentially since when we upgraded the FTD about 9 days ago.&lt;/P&gt;&lt;P&gt;Only one of the peers is down and others are working fine, and we can ping the destination so L2 appears to be fine.&lt;/P&gt;&lt;P&gt;Anyway, we didn't get any notifications and only found this by chance, and after seeing some posts at this forum etc started looking at updating the syslog setting as we've kept the syslog settings in Platform Settings pretty much default.&amp;nbsp;&lt;/P&gt;&lt;P&gt;It seems that FTD syslog messages are somewhat limited compared to ASA syslog messages as there are only 1 BGP related&amp;nbsp; syslog message (317007) available for FTD, whereas ASA has 4 (317007,&amp;nbsp;418018, 418019, 418040).&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/Syslogs/b_fptd_syslog_guide.html" target="_blank" rel="noopener"&gt;Cisco Secure Firewall Threat Defense Syslog Messages - Cisco&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/syslog/b_syslog.html" target="_blank" rel="noopener"&gt;Cisco Secure Firewall ASA Series Syslog Messages - Cisco&lt;/A&gt;&lt;/P&gt;&lt;P&gt;In any case, upon trying to add 317007 for FTD, I get this which suggest it is not available:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="atsukane_0-1720604983337.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/223055iCF51EDA6F012E767/image-size/medium?v=v2&amp;amp;px=400" role="button" title="atsukane_0-1720604983337.png" alt="atsukane_0-1720604983337.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;And trying to add it anyway I receive "invalid syslog id" error.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="atsukane_2-1720605465546.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/223057i62519BA15A2995B8/image-size/medium?v=v2&amp;amp;px=400" role="button" title="atsukane_2-1720605465546.png" alt="atsukane_2-1720605465546.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;How do we go about enabling alerts when BGP peer/s go down?&lt;/P&gt;&lt;P&gt;We've got Solorwinds NPM as a syslog server and also snmp server.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please advise.&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2024 11:04:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/bgp-syslog-messages-on-ftd/m-p/5142748#M1114157</guid>
      <dc:creator>atsukane</dc:creator>
      <dc:date>2024-07-10T11:04:44Z</dc:date>
    </item>
    <item>
      <title>Re: BGP Syslog messages on FTD</title>
      <link>https://community.cisco.com/t5/network-security/bgp-syslog-messages-on-ftd/m-p/5142795#M1114159</link>
      <description>&lt;P&gt;Is the log neighbor changes option enabled under BGP General settings?&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2024 11:19:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/bgp-syslog-messages-on-ftd/m-p/5142795#M1114159</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2024-07-10T11:19:40Z</dc:date>
    </item>
    <item>
      <title>Re: BGP Syslog messages on FTD</title>
      <link>https://community.cisco.com/t5/network-security/bgp-syslog-messages-on-ftd/m-p/5142799#M1114160</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/319690"&gt;@Marius Gunnerud&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, it is enabled.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="atsukane_0-1720610505748.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/223070iEA3AE0925AB25161/image-size/medium?v=v2&amp;amp;px=400" role="button" title="atsukane_0-1720610505748.png" alt="atsukane_0-1720610505748.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2024 11:23:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/bgp-syslog-messages-on-ftd/m-p/5142799#M1114160</guid>
      <dc:creator>atsukane</dc:creator>
      <dc:date>2024-07-10T11:23:10Z</dc:date>
    </item>
    <item>
      <title>Re: BGP Syslog messages on FTD</title>
      <link>https://community.cisco.com/t5/network-security/bgp-syslog-messages-on-ftd/m-p/5142810#M1114162</link>
      <description>&lt;P&gt;found this entry in another syslog&amp;nbsp; (XDR), it would appear that inbound traffic from the peer is dropped by the firewall??&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="atsukane_2-1720610949022.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/223072i608252010B824C77/image-size/medium?v=v2&amp;amp;px=400" role="button" title="atsukane_2-1720610949022.png" alt="atsukane_2-1720610949022.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2024 11:29:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/bgp-syslog-messages-on-ftd/m-p/5142810#M1114162</guid>
      <dc:creator>atsukane</dc:creator>
      <dc:date>2024-07-10T11:29:35Z</dc:date>
    </item>
    <item>
      <title>Re: BGP Syslog messages on FTD</title>
      <link>https://community.cisco.com/t5/network-security/bgp-syslog-messages-on-ftd/m-p/5142818#M1114163</link>
      <description>&lt;P&gt;Yes, that is dropping the BGP connection.&amp;nbsp; Any chance at allowing it?&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2024 11:36:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/bgp-syslog-messages-on-ftd/m-p/5142818#M1114163</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2024-07-10T11:36:57Z</dc:date>
    </item>
    <item>
      <title>Re: BGP Syslog messages on FTD</title>
      <link>https://community.cisco.com/t5/network-security/bgp-syslog-messages-on-ftd/m-p/5142822#M1114164</link>
      <description>&lt;P&gt;In bgp there are two peers&amp;nbsp;&lt;/P&gt;
&lt;P&gt;One use unknown port other use known port 179&lt;/P&gt;
&lt;P&gt;So when ypu add policy did ypu use port 179 ?&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2024 11:44:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/bgp-syslog-messages-on-ftd/m-p/5142822#M1114164</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-07-10T11:44:57Z</dc:date>
    </item>
    <item>
      <title>Re: BGP Syslog messages on FTD</title>
      <link>https://community.cisco.com/t5/network-security/bgp-syslog-messages-on-ftd/m-p/5142826#M1114165</link>
      <description>&lt;P&gt;Adding a rule allowing the destination port tcp/179. Let's see how that goes.&lt;/P&gt;&lt;P&gt;Odd that we have no rules for other peers that are working.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="atsukane_0-1720612256851.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/223074iB2489553D8FB25A3/image-size/medium?v=v2&amp;amp;px=400" role="button" title="atsukane_0-1720612256851.png" alt="atsukane_0-1720612256851.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2024 11:52:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/bgp-syslog-messages-on-ftd/m-p/5142826#M1114165</guid>
      <dc:creator>atsukane</dc:creator>
      <dc:date>2024-07-10T11:52:36Z</dc:date>
    </item>
    <item>
      <title>Re: BGP Syslog messages on FTD</title>
      <link>https://community.cisco.com/t5/network-security/bgp-syslog-messages-on-ftd/m-p/5142839#M1114166</link>
      <description>&lt;P&gt;To the box traffic normally does not use regular access rules, so it is strange that you are seeing this being dropped.&amp;nbsp; But depending on which interface you are using to establish neighbors this opening might be needed.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2024 12:04:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/bgp-syslog-messages-on-ftd/m-p/5142839#M1114166</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2024-07-10T12:04:28Z</dc:date>
    </item>
    <item>
      <title>Re: BGP Syslog messages on FTD</title>
      <link>https://community.cisco.com/t5/network-security/bgp-syslog-messages-on-ftd/m-p/5142850#M1114167</link>
      <description>&lt;P&gt;Unfortunately, adding a rule to allow tcp179 didn't help &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Will log a ticket with our support firm and come back with the findings for the resolution.&lt;/P&gt;&lt;P&gt;Still like to know how to enable monitoring and alerts if anyone has any ideas.&lt;/P&gt;&lt;P&gt;Thanks,&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2024 12:14:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/bgp-syslog-messages-on-ftd/m-p/5142850#M1114167</guid>
      <dc:creator>atsukane</dc:creator>
      <dc:date>2024-07-10T12:14:40Z</dc:date>
    </item>
    <item>
      <title>Re: BGP Syslog messages on FTD</title>
      <link>https://community.cisco.com/t5/network-security/bgp-syslog-messages-on-ftd/m-p/5142987#M1114177</link>
      <description>&lt;P&gt;Mr &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/319690"&gt;@Marius Gunnerud&lt;/a&gt;&amp;nbsp;is correct ACL dont effect to box traffic the ACL control plane only effect that.&lt;/P&gt;
&lt;P&gt;For this peer the bgp is down can ypu check if address family is disable or enable.&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2024 16:57:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/bgp-syslog-messages-on-ftd/m-p/5142987#M1114177</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-07-10T16:57:10Z</dc:date>
    </item>
    <item>
      <title>Re: BGP Syslog messages on FTD</title>
      <link>https://community.cisco.com/t5/network-security/bgp-syslog-messages-on-ftd/m-p/5145409#M1114318</link>
      <description>&lt;P&gt;Just returned to update the BGP issue we've had.&lt;/P&gt;&lt;P&gt;It would appear that FTD has somehow modified the BGP key following the upgrade from 7.2.6 to 7.2.7.&lt;/P&gt;&lt;P&gt;"more system:running-config" output was showing the wrong key, missing the first 2 characters, in our case "0x".&lt;/P&gt;&lt;P&gt;Re-applying the correct key on the FTD has resolve the issue.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jul 2024 08:27:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/bgp-syslog-messages-on-ftd/m-p/5145409#M1114318</guid>
      <dc:creator>atsukane</dc:creator>
      <dc:date>2024-07-16T08:27:44Z</dc:date>
    </item>
    <item>
      <title>Re: BGP Syslog messages on FTD</title>
      <link>https://community.cisco.com/t5/network-security/bgp-syslog-messages-on-ftd/m-p/5145443#M1114321</link>
      <description>&lt;P&gt;Thanks a lot for update us&lt;/P&gt;
&lt;P&gt;Have a nice summer&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jul 2024 09:22:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/bgp-syslog-messages-on-ftd/m-p/5145443#M1114321</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-07-16T09:22:54Z</dc:date>
    </item>
    <item>
      <title>Re: BGP Syslog messages on FTD</title>
      <link>https://community.cisco.com/t5/network-security/bgp-syslog-messages-on-ftd/m-p/5145571#M1114328</link>
      <description>&lt;P&gt;Noticed Soalrwinds is seeing "FTD-3-418018"&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="atsukane_0-1721135106535.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/223550i461BC72966AE5360/image-size/medium?v=v2&amp;amp;px=400" role="button" title="atsukane_0-1721135106535.png" alt="atsukane_0-1721135106535.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;So manually added 418018 with the "error" level on the platform settings and added email set up to email me severity erros as a test, but not playing ball &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="atsukane_1-1721135256240.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/223551i068B041D6BA92D71/image-size/medium?v=v2&amp;amp;px=400" role="button" title="atsukane_1-1721135256240.png" alt="atsukane_1-1721135256240.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I'll play around a bit more and post updates if i find anything. Leaning Solarwinds alerting on the fly!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jul 2024 13:55:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/bgp-syslog-messages-on-ftd/m-p/5145571#M1114328</guid>
      <dc:creator>atsukane</dc:creator>
      <dc:date>2024-07-16T13:55:38Z</dc:date>
    </item>
  </channel>
</rss>

