<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX/ASA Syslog using TCP in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-asa-syslog-using-tcp/m-p/793373#M422358</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In my experience, it won't recover, but that was with 7.0, I think.  I doubt that it's changed, but it was enough to prevent using TCP logging for us.  Some drops were better than no logging...however, it is possible to make the firewall stop passing traffic if logging fails, I believe, so that could be used as an avenue toward recovery, if the tradeoff is acceptable.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;George&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 06 Apr 2007 20:58:28 GMT</pubDate>
    <dc:creator>kofflerg</dc:creator>
    <dc:date>2007-04-06T20:58:28Z</dc:date>
    <item>
      <title>PIX/ASA Syslog using TCP</title>
      <link>https://community.cisco.com/t5/network-security/pix-asa-syslog-using-tcp/m-p/793372#M422357</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Reading the PIX documentation (v7.2) I can find the following regarding logging host configuration: " If you specify TCP, the security appliance discovers when the syslog server fails and discontinues sending logs"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Will the firewall recover syslog service (i.e. restarts sending logs) after the server becomes online again? or manual intervention will be needed?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ricardo&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 09:28:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-asa-syslog-using-tcp/m-p/793372#M422357</guid>
      <dc:creator>rlourenco</dc:creator>
      <dc:date>2020-02-21T09:28:19Z</dc:date>
    </item>
    <item>
      <title>Re: PIX/ASA Syslog using TCP</title>
      <link>https://community.cisco.com/t5/network-security/pix-asa-syslog-using-tcp/m-p/793373#M422358</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In my experience, it won't recover, but that was with 7.0, I think.  I doubt that it's changed, but it was enough to prevent using TCP logging for us.  Some drops were better than no logging...however, it is possible to make the firewall stop passing traffic if logging fails, I believe, so that could be used as an avenue toward recovery, if the tradeoff is acceptable.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;George&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Apr 2007 20:58:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-asa-syslog-using-tcp/m-p/793373#M422358</guid>
      <dc:creator>kofflerg</dc:creator>
      <dc:date>2007-04-06T20:58:28Z</dc:date>
    </item>
  </channel>
</rss>

