<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Syslog best practices in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/syslog-best-practices/m-p/2220151#M347986</link>
    <description>&lt;P&gt;We need to have our syslog server facing the internet to aid in troubleshooting clients.&amp;nbsp; And it's random when I'd need it and I'd rather not be going back to the firewall and opening the port while i need it, shut it down later, open it again, and so on.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;those with public facing syslog servers, what do you do?&amp;nbsp; just open up udp514 and hope for the best?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for some input.&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 01:58:23 GMT</pubDate>
    <dc:creator>WStoffel1</dc:creator>
    <dc:date>2019-03-12T01:58:23Z</dc:date>
    <item>
      <title>Syslog best practices</title>
      <link>https://community.cisco.com/t5/network-security/syslog-best-practices/m-p/2220151#M347986</link>
      <description>&lt;P&gt;We need to have our syslog server facing the internet to aid in troubleshooting clients.&amp;nbsp; And it's random when I'd need it and I'd rather not be going back to the firewall and opening the port while i need it, shut it down later, open it again, and so on.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;those with public facing syslog servers, what do you do?&amp;nbsp; just open up udp514 and hope for the best?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for some input.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 01:58:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/syslog-best-practices/m-p/2220151#M347986</guid>
      <dc:creator>WStoffel1</dc:creator>
      <dc:date>2019-03-12T01:58:23Z</dc:date>
    </item>
    <item>
      <title>Syslog best practices</title>
      <link>https://community.cisco.com/t5/network-security/syslog-best-practices/m-p/2220152#M347987</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We if we are talking about ASA firewall then I guess you can always create an ACL rule for all the customers that you might need to open up the Syslog traffic for. When you dont need to have those ports open on the ASA then you can turn them "inactive" either trought the ASDM or CLI and leave the actual rules to the configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Naturally if you are sending Syslog through the Internet you might want to consider perhaps even building a L2L VPN connection between your site and the customer site and tunneling their Syslog traffic through that L2L VPN connection. I have for example a couple of times configured L2L VPN between an ASA and one of our VPN gateway so that the remote customer ASA can sends its own Syslogs through the L2L VPN connection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then I guess you might want to consider configuring the Syslog to use TCP instead of UDP on the ASA. In this case I would recommend using "logging permit-hostdown" command since if you dont have it configured on an ASA and enable TCP Syslogging which for some reason isnt able to contact the Syslog server then ALL traffic through the ASA will be blocked. And you probably wont want that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not sure if there is any convinien way to manage the rules either than maybe handle setting them "active" or "inactive" through the ASDM. I would imagine in this case the managing of those rules would be faster and more convinient through ASDM even though I personally do all ACL configurations through the CLI&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 15 Jun 2013 11:31:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/syslog-best-practices/m-p/2220152#M347987</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-06-15T11:31:33Z</dc:date>
    </item>
    <item>
      <title>Syslog best practices</title>
      <link>https://community.cisco.com/t5/network-security/syslog-best-practices/m-p/2220153#M347988</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As always, thanks for the insightful help!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Jun 2013 17:24:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/syslog-best-practices/m-p/2220153#M347988</guid>
      <dc:creator>WStoffel1</dc:creator>
      <dc:date>2013-06-17T17:24:19Z</dc:date>
    </item>
    <item>
      <title>Syslog best practices</title>
      <link>https://community.cisco.com/t5/network-security/syslog-best-practices/m-p/2220154#M347989</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Glad if it was of some help &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please do take the time to either mark the reply as the correct answer IF it answered your question. Or rate helpfull answers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Jun 2013 17:27:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/syslog-best-practices/m-p/2220154#M347989</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-06-17T17:27:54Z</dc:date>
    </item>
  </channel>
</rss>

