<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX Logging in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-logging/m-p/313354#M552467</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I normally use 'log buff warn'&lt;/P&gt;&lt;P&gt;Nice and easy to 'clear log' and see up to date entries, nothing clogging your screen up when trying to configure.&lt;/P&gt;&lt;P&gt;Obviously if your pix is letting this straight through, you're not going to see it in the log, but if you're looking for attacks that your pix is currently protecting you from, it will be there.&lt;/P&gt;&lt;P&gt;Tighten up the pix where necessary and you can quickly see any genuine traffic you may have stopped inadvertantly.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 20 Jan 2005 00:47:02 GMT</pubDate>
    <dc:creator>garethhinton</dc:creator>
    <dc:date>2005-01-20T00:47:02Z</dc:date>
    <item>
      <title>PIX Logging</title>
      <link>https://community.cisco.com/t5/network-security/pix-logging/m-p/313352#M552463</link>
      <description>&lt;P&gt;If I suspect that my network is under attack, what level should I be logging, and what should I be looking for, to tell if someone is attempting to attack my network?  Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 07:52:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-logging/m-p/313352#M552463</guid>
      <dc:creator>mtobkes</dc:creator>
      <dc:date>2020-02-21T07:52:58Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Logging</title>
      <link>https://community.cisco.com/t5/network-security/pix-logging/m-p/313353#M552464</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Warning for logging should be fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Take a look for DROP packets from the same source IP. If a SYN Flooding is the problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have Public services as http, smtp or others?&lt;/P&gt;&lt;P&gt;I suppose yes, then take a look if you have exessive amount of SYN packets on the protocol.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Easyest way to do that is putting a sniffer in place and do some statistical work.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Another way could be to put a NTOP host on the internet. &lt;A class="jive-link-custom" href="http://www.ntop.org/ntop.html" target="_blank"&gt;http://www.ntop.org/ntop.html&lt;/A&gt; to see real time traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sincerely&lt;/P&gt;&lt;P&gt;Patrick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Jan 2005 00:42:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-logging/m-p/313353#M552464</guid>
      <dc:creator>Patrick Iseli</dc:creator>
      <dc:date>2005-01-20T00:42:04Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Logging</title>
      <link>https://community.cisco.com/t5/network-security/pix-logging/m-p/313354#M552467</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I normally use 'log buff warn'&lt;/P&gt;&lt;P&gt;Nice and easy to 'clear log' and see up to date entries, nothing clogging your screen up when trying to configure.&lt;/P&gt;&lt;P&gt;Obviously if your pix is letting this straight through, you're not going to see it in the log, but if you're looking for attacks that your pix is currently protecting you from, it will be there.&lt;/P&gt;&lt;P&gt;Tighten up the pix where necessary and you can quickly see any genuine traffic you may have stopped inadvertantly.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Jan 2005 00:47:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-logging/m-p/313354#M552467</guid>
      <dc:creator>garethhinton</dc:creator>
      <dc:date>2005-01-20T00:47:02Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Logging</title>
      <link>https://community.cisco.com/t5/network-security/pix-logging/m-p/313355#M552469</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm not a big big specialist as others, but the real good solution is to set it to Notifications. Why?&lt;/P&gt;&lt;P&gt;1. On each access-list apply logging policy. &lt;/P&gt;&lt;P&gt;2. Install Kiwi (any syslog server)&lt;/P&gt;&lt;P&gt;3. You will not be able to determine the attack that's going in a wright way. That's why you need to log all the event's in a case that you will need the evidence.&lt;/P&gt;&lt;P&gt;4. Check all your servers that STATIC command translates. In the Event logs you can find a lot of interesting staff.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And after one day that you capture syslog messages, sit on them for a day, and try to analyze.&lt;/P&gt;&lt;P&gt;I usually do so. &lt;/P&gt;&lt;P&gt;Example is simple:&lt;/P&gt;&lt;P&gt;Somebone usually come to my web-site from such a site &lt;A class="jive-link-custom" href="http://www.anonymizer.com/" target="_blank"&gt;www.anonymizer.com/&lt;/A&gt; What does it mean for any security specialist...right! He want's only look on a pictures on my site &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Jan 2005 20:13:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-logging/m-p/313355#M552469</guid>
      <dc:creator>Paul Greenberg</dc:creator>
      <dc:date>2005-01-20T20:13:58Z</dc:date>
    </item>
  </channel>
</rss>

