<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX syslog to sensor in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-syslog-to-sensor/m-p/36566#M687520</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;the sensor cannot do this. The sensor will only accept syslog messages from routers that it is using for shunning. Why dont you configure the pix to notify the director? you must be using pix 6.0 or higher.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 06 Nov 2001 13:53:00 GMT</pubDate>
    <dc:creator>jawelsh</dc:creator>
    <dc:date>2001-11-06T13:53:00Z</dc:date>
    <item>
      <title>PIX syslog to sensor</title>
      <link>https://community.cisco.com/t5/network-security/pix-syslog-to-sensor/m-p/36565#M687503</link>
      <description>&lt;P&gt;Does anyone know if a sensor can be configured to interpret PIX syslog/IDS messages and notify the director? Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 05:53:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-syslog-to-sensor/m-p/36565#M687503</guid>
      <dc:creator>tednie</dc:creator>
      <dc:date>2020-02-21T05:53:50Z</dc:date>
    </item>
    <item>
      <title>Re: PIX syslog to sensor</title>
      <link>https://community.cisco.com/t5/network-security/pix-syslog-to-sensor/m-p/36566#M687520</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;the sensor cannot do this. The sensor will only accept syslog messages from routers that it is using for shunning. Why dont you configure the pix to notify the director? you must be using pix 6.0 or higher.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Nov 2001 13:53:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-syslog-to-sensor/m-p/36566#M687520</guid>
      <dc:creator>jawelsh</dc:creator>
      <dc:date>2001-11-06T13:53:00Z</dc:date>
    </item>
    <item>
      <title>Re: PIX syslog to sensor</title>
      <link>https://community.cisco.com/t5/network-security/pix-syslog-to-sensor/m-p/36567#M687529</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I can't find any commands similiar to the router IOS IDS commands on the PIX, enabling the po protocol for communication to the director. Unless you mean just log out to the syslog service.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Nov 2001 14:57:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-syslog-to-sensor/m-p/36567#M687529</guid>
      <dc:creator>tednie</dc:creator>
      <dc:date>2001-11-06T14:57:59Z</dc:date>
    </item>
    <item>
      <title>Re: PIX syslog to sensor</title>
      <link>https://community.cisco.com/t5/network-security/pix-syslog-to-sensor/m-p/36568#M687545</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You are correct that the Pix did not port the Postoffice protocol when they implemented IDS on the Pix.&lt;/P&gt;&lt;P&gt;So you would have to rely on the syslog messages generated by the Pix.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CSPM is able to receive both the alarms generated by the IDS sensors and the syslog messages from the Pix.&lt;/P&gt;&lt;P&gt;They are not viewed in the same windows nor appear in the same reports, so you will have to look at both the syslog reports from the Pix and the IDS alarms.  I believe that there might already be initiaives to correlate the data from the two message types in a future product, but I don't know any details&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If using the Unix Director then you will have to rely on a third package for viewing the syslog data for the Pix.&lt;/P&gt;&lt;P&gt;You could look for syslog analyzers that are not security specific or  you can purchase NetForensics which is able to receive alarms from the IDS sensors as well as the syslog messages from the Pix.  I believe that it supposed to be able to coordinate data from the IDS sensor alarms in the syslog messages wiht some type of links, but I have not tried it myself.  I would reccomend contacting NetForensics directly if that interests you: &lt;A class="jive-link-custom" href="http://www.netforensics.com" target="_blank"&gt;www.netforensics.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Nov 2001 17:34:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-syslog-to-sensor/m-p/36568#M687545</guid>
      <dc:creator>marcabal</dc:creator>
      <dc:date>2001-11-06T17:34:08Z</dc:date>
    </item>
  </channel>
</rss>

