<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic sec mon &amp; PIX monitoring in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/sec-mon-pix-monitoring/m-p/299493#M563606</link>
    <description>&lt;P&gt;Iam currently using Security Monitor 1.2.3 to monitor IDS 4235 events. I have added Cisco PIX 515 to the list fo devices to be monitored by Sec Mon. The only problem is that I am NOT getting any message from PIX in the events window.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. The instruction did NOT state that I need to configure the PIX to send events to the Sec Mon. Do I need to do so? If so, exactly what do I need to do on the PIX so as to forward messages (events, alarms, alerts) to Sec Mon.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. What ports must I open on the PIX so as to enable sending of messages. I suspect taht perhaps port 161 and 162? If so, please confirm.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3. While in Sec Mon, I checjed for "connections" which would give me the status of devices monitored voa Sec Mon. I only saw the IDS sensors. I suspect that perhaps PIX woudl not appear in the lsit because it is noit a RDEP device. Is that correct or shoudl I see PIX in the list.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Ade&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 07:32:19 GMT</pubDate>
    <dc:creator>infinitingr2</dc:creator>
    <dc:date>2020-02-21T07:32:19Z</dc:date>
    <item>
      <title>sec mon &amp; PIX monitoring</title>
      <link>https://community.cisco.com/t5/network-security/sec-mon-pix-monitoring/m-p/299493#M563606</link>
      <description>&lt;P&gt;Iam currently using Security Monitor 1.2.3 to monitor IDS 4235 events. I have added Cisco PIX 515 to the list fo devices to be monitored by Sec Mon. The only problem is that I am NOT getting any message from PIX in the events window.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. The instruction did NOT state that I need to configure the PIX to send events to the Sec Mon. Do I need to do so? If so, exactly what do I need to do on the PIX so as to forward messages (events, alarms, alerts) to Sec Mon.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. What ports must I open on the PIX so as to enable sending of messages. I suspect taht perhaps port 161 and 162? If so, please confirm.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3. While in Sec Mon, I checjed for "connections" which would give me the status of devices monitored voa Sec Mon. I only saw the IDS sensors. I suspect that perhaps PIX woudl not appear in the lsit because it is noit a RDEP device. Is that correct or shoudl I see PIX in the list.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Ade&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 07:32:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sec-mon-pix-monitoring/m-p/299493#M563606</guid>
      <dc:creator>infinitingr2</dc:creator>
      <dc:date>2020-02-21T07:32:19Z</dc:date>
    </item>
    <item>
      <title>Re: sec mon &amp; PIX monitoring</title>
      <link>https://community.cisco.com/t5/network-security/sec-mon-pix-monitoring/m-p/299494#M563608</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ade,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to setup PIX to send syslog messages to the PIXMC. No ports needed to be opened. Just enable sysloging and thats it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the connections you will only see IDS as connected tls&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Nadeem&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Jul 2004 20:58:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sec-mon-pix-monitoring/m-p/299494#M563608</guid>
      <dc:creator>nkhawaja</dc:creator>
      <dc:date>2004-07-30T20:58:34Z</dc:date>
    </item>
    <item>
      <title>Re: sec mon &amp; PIX monitoring</title>
      <link>https://community.cisco.com/t5/network-security/sec-mon-pix-monitoring/m-p/299495#M563611</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To set up logging from the PIX you need to specify the IP address of your sec mon server and which interface it can be reached through&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;e.g. logging host inside 10.0.0.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Set your logging severity&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;e.g. logging trap debugging&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This will send all debug messages to Sec Mon&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also remember to turn logging on!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The following link covers the logging command on the PIX&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/sw/secursw/ps2120/products_command_reference_chapter09186a00801727a9.html#wp1028090" target="_blank"&gt;http://www.cisco.com/en/US/products/sw/secursw/ps2120/products_command_reference_chapter09186a00801727a9.html#wp1028090&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ports you mentioned (161 &amp;amp; 162) are for SNMP which is not required for syslogging, plus i belive the PIX doesn't filter on traffic that's sourced from itself.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm afraid i haven't used security monitor so i can't comment on your other question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds&lt;/P&gt;&lt;P&gt;Paddy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 31 Jul 2004 12:38:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sec-mon-pix-monitoring/m-p/299495#M563611</guid>
      <dc:creator>paddyxdoyle</dc:creator>
      <dc:date>2004-07-31T12:38:11Z</dc:date>
    </item>
  </channel>
</rss>

