<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX/PDM/Syslog rule number in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-pdm-syslog-rule-number/m-p/389478#M555961</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;1)  There's a link in that you can use the numbers to insert new lines at arbitrary places in an access-lists, but aside from this ACL editing feature there's no other significance to the line numbers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2)  The syslog messages won't reference the individual ACL line numbers, but you can get increased detail by configuring ACL logging on individual ACL lines.  The message lists which ACL was involved and the details of the protocol, and source and destination ports and addresses, but they don't specifically identify the actual ACL line that matched the packet.  However, the log information in conjunction with the hit count in the "show access-list" command should allow you to determine the line reasonably easily, depending on how complex your ACL is, of course.  This doesn't help 3rd party syslog tools report details on the ACL, but it might help you make the connection between the log message and the ACL entry more easily.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 22 Oct 2004 17:06:03 GMT</pubDate>
    <dc:creator>ddawson</dc:creator>
    <dc:date>2004-10-22T17:06:03Z</dc:date>
    <item>
      <title>PIX/PDM/Syslog rule number</title>
      <link>https://community.cisco.com/t5/network-security/pix-pdm-syslog-rule-number/m-p/389477#M555958</link>
      <description>&lt;P&gt;Looking at the Pix Device Manager I can see access rules associated with reference numbers, just like many other vendors' firewall GUIs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now my questions are:&lt;/P&gt;&lt;P&gt;1) What is the link between such reference numbers and the actual PIX config file ?&lt;/P&gt;&lt;P&gt;2) Is there a way to insert such reference numbers into the syslog messages that the PIX sends out, in order to analyze the syslogs with 3rd party reporting tools ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for collabations&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Andrea&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 07:41:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-pdm-syslog-rule-number/m-p/389477#M555958</guid>
      <dc:creator>apasquino</dc:creator>
      <dc:date>2020-02-21T07:41:57Z</dc:date>
    </item>
    <item>
      <title>Re: PIX/PDM/Syslog rule number</title>
      <link>https://community.cisco.com/t5/network-security/pix-pdm-syslog-rule-number/m-p/389478#M555961</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;1)  There's a link in that you can use the numbers to insert new lines at arbitrary places in an access-lists, but aside from this ACL editing feature there's no other significance to the line numbers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2)  The syslog messages won't reference the individual ACL line numbers, but you can get increased detail by configuring ACL logging on individual ACL lines.  The message lists which ACL was involved and the details of the protocol, and source and destination ports and addresses, but they don't specifically identify the actual ACL line that matched the packet.  However, the log information in conjunction with the hit count in the "show access-list" command should allow you to determine the line reasonably easily, depending on how complex your ACL is, of course.  This doesn't help 3rd party syslog tools report details on the ACL, but it might help you make the connection between the log message and the ACL entry more easily.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Oct 2004 17:06:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-pdm-syslog-rule-number/m-p/389478#M555961</guid>
      <dc:creator>ddawson</dc:creator>
      <dc:date>2004-10-22T17:06:03Z</dc:date>
    </item>
  </channel>
</rss>

