<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic PIX 515E xlate logging in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-515e-xlate-logging/m-p/223616#M568235</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;   We have placed a 515E on our network and we want to be able to log who was what external IP address(or PAT port) when. It seems like a feature that everyone would use but for the life of me I can not figure it out. Have setup syslog but it does not help, nothing or to verbose(Every TCP connection logged). Figured it is something simple that I am over looking, Tryed a SNMP walk but could not find this data this way either. Could make a cronjob user that can only get the xlate but I am hoping there is a better way. Thanks for any help you can give...Scott&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 07:15:59 GMT</pubDate>
    <dc:creator>sdaniels</dc:creator>
    <dc:date>2020-02-21T07:15:59Z</dc:date>
    <item>
      <title>PIX 515E xlate logging</title>
      <link>https://community.cisco.com/t5/network-security/pix-515e-xlate-logging/m-p/223616#M568235</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;   We have placed a 515E on our network and we want to be able to log who was what external IP address(or PAT port) when. It seems like a feature that everyone would use but for the life of me I can not figure it out. Have setup syslog but it does not help, nothing or to verbose(Every TCP connection logged). Figured it is something simple that I am over looking, Tryed a SNMP walk but could not find this data this way either. Could make a cronjob user that can only get the xlate but I am hoping there is a better way. Thanks for any help you can give...Scott&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 07:15:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515e-xlate-logging/m-p/223616#M568235</guid>
      <dc:creator>sdaniels</dc:creator>
      <dc:date>2020-02-21T07:15:59Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515E xlate logging</title>
      <link>https://community.cisco.com/t5/network-security/pix-515e-xlate-logging/m-p/223617#M568236</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SYSLOGS, with probably a logging level of 6, or 7. would give you information about the connections being made from what local to what global address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;Nadeem&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 01 Mar 2004 21:16:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515e-xlate-logging/m-p/223617#M568236</guid>
      <dc:creator>nkhawaja</dc:creator>
      <dc:date>2004-03-01T21:16:41Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515E xlate logging</title>
      <link>https://community.cisco.com/t5/network-security/pix-515e-xlate-logging/m-p/223618#M568237</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My guess is that you are looking for syslog messages 305011 and 305012 (&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_sw/v_63/63syslog/pixemsgs.htm" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_sw/v_63/63syslog/pixemsgs.htm&lt;/A&gt;).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As Nadeem mentioned, these are level 6 messages in the 6.3 code.  The problem with logging at level 6 (as you have seen) is that you get a *lot* of other info as well.  If you are only interested in getting these 2 messages from the level 6 syslogs, you can change the default level they are given in the 6.3 code.  For instance, let's say you normally just send level 3 and below messages to your syslog server.  In the 6.3 code, you now have the option to assign syslog ID 305011 and 305012 as level 3 messages as well.  This way, you get the info you need without overwhelming your syslog server with info you don't want.  Here is a link that discusses this config parameter on the PIX:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_sw/v_63/cmdref/gl.htm#1028090" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_sw/v_63/cmdref/gl.htm#1028090&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Good luck and let us know if you have any other questions concerning this or if this does not answer you question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Mar 2004 14:20:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515e-xlate-logging/m-p/223618#M568237</guid>
      <dc:creator>scoclayton</dc:creator>
      <dc:date>2004-03-02T14:20:52Z</dc:date>
    </item>
  </channel>
</rss>

