<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Pix and Syslog in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-and-syslog/m-p/471914#M531204</link>
    <description>&lt;P&gt;We have noticed that when the syslog server becomes unavailable that the pix generates large amounts of ICMP reverse path check errors. Can some one explain why this happens and if it can be prevented. &lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;marcus&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 08:29:48 GMT</pubDate>
    <dc:creator>mgaysek</dc:creator>
    <dc:date>2020-02-21T08:29:48Z</dc:date>
    <item>
      <title>Pix and Syslog</title>
      <link>https://community.cisco.com/t5/network-security/pix-and-syslog/m-p/471914#M531204</link>
      <description>&lt;P&gt;We have noticed that when the syslog server becomes unavailable that the pix generates large amounts of ICMP reverse path check errors. Can some one explain why this happens and if it can be prevented. &lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;marcus&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 08:29:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-and-syslog/m-p/471914#M531204</guid>
      <dc:creator>mgaysek</dc:creator>
      <dc:date>2020-02-21T08:29:48Z</dc:date>
    </item>
    <item>
      <title>Re: Pix and Syslog</title>
      <link>https://community.cisco.com/t5/network-security/pix-and-syslog/m-p/471915#M531208</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By disabling the syslog server, you are effectively DoSing the PIX.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PIX sends syslog message to Windows based syslogs server on UDP port 514.&lt;/P&gt;&lt;P&gt;Windows doesn't have a service listening on that port, so it sends back a port unreachable message.  That ICMP message gets back to the PIX, where&lt;/P&gt;&lt;P&gt;"ip audit" is applied to the interface, causing the PIX to generate a syslog for the Unreachable message it got from the syslog server in response to the syslog that the PIX originaly sent it.  Got it ;-0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The solution is to disable the logging of the ICMP unreachable message, or disable the audit command or removing the logging host command if the syslog server is unavailable.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Franco Zamora&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 31 Oct 2005 14:17:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-and-syslog/m-p/471915#M531208</guid>
      <dc:creator>fzamora</dc:creator>
      <dc:date>2005-10-31T14:17:55Z</dc:date>
    </item>
    <item>
      <title>Re: Pix and Syslog</title>
      <link>https://community.cisco.com/t5/network-security/pix-and-syslog/m-p/471916#M531210</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Great! thank you... does the same happen on unix based syslog servers?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 31 Oct 2005 14:58:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-and-syslog/m-p/471916#M531210</guid>
      <dc:creator>mgaysek</dc:creator>
      <dc:date>2005-10-31T14:58:41Z</dc:date>
    </item>
    <item>
      <title>Re: Pix and Syslog</title>
      <link>https://community.cisco.com/t5/network-security/pix-and-syslog/m-p/471917#M531212</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If the UNIX does not have a listening port, I assume the behavior will be the same.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Franco&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 31 Oct 2005 15:40:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-and-syslog/m-p/471917#M531212</guid>
      <dc:creator>fzamora</dc:creator>
      <dc:date>2005-10-31T15:40:29Z</dc:date>
    </item>
  </channel>
</rss>

