<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Logging PIX xlates? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/logging-pix-xlates/m-p/61568#M707779</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;the pix message that tracks connections is&lt;/P&gt;&lt;P&gt;pix-6-305002. BUT:&lt;/P&gt;&lt;P&gt;in a hih traffic network, this will impact performance greatly. Its an informational message.&lt;/P&gt;&lt;P&gt;I would suggest that you send it to a syslog server,&lt;/P&gt;&lt;P&gt;&amp;amp; then parse the output to a readable form. Don't forget timestamping.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 20 Sep 2001 17:11:48 GMT</pubDate>
    <dc:creator>millerv</dc:creator>
    <dc:date>2001-09-20T17:11:48Z</dc:date>
    <item>
      <title>Logging PIX xlates?</title>
      <link>https://community.cisco.com/t5/network-security/logging-pix-xlates/m-p/61567#M707778</link>
      <description>&lt;P&gt;Is it possible to log the xlates occuring in a PIX firewall so I can go back later and see what internal address mapped to a particular external address?  We have our xlate time set rather high because of the high volume of use our students have on the network and the need to be good stewards of our address space.  Yet now, I am having some locations indicating some possible port scanning going on.  By the time these locations contact me the xlate has long since changed to a different user.  Is there any way to log xlates by time and date either on the pix for so long or externally using CISCOWorks or something else?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thomas Knight&lt;/P&gt;&lt;P&gt;Taylor University&lt;/P&gt;&lt;P&gt;&lt;A href="mailto:thknight@tayloru.edu" target="_blank"&gt;thknight@tayloru.edu&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 05:49:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/logging-pix-xlates/m-p/61567#M707778</guid>
      <dc:creator>thknight</dc:creator>
      <dc:date>2020-02-21T05:49:49Z</dc:date>
    </item>
    <item>
      <title>Re: Logging PIX xlates?</title>
      <link>https://community.cisco.com/t5/network-security/logging-pix-xlates/m-p/61568#M707779</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;the pix message that tracks connections is&lt;/P&gt;&lt;P&gt;pix-6-305002. BUT:&lt;/P&gt;&lt;P&gt;in a hih traffic network, this will impact performance greatly. Its an informational message.&lt;/P&gt;&lt;P&gt;I would suggest that you send it to a syslog server,&lt;/P&gt;&lt;P&gt;&amp;amp; then parse the output to a readable form. Don't forget timestamping.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Sep 2001 17:11:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/logging-pix-xlates/m-p/61568#M707779</guid>
      <dc:creator>millerv</dc:creator>
      <dc:date>2001-09-20T17:11:48Z</dc:date>
    </item>
    <item>
      <title>Re: Logging PIX xlates?</title>
      <link>https://community.cisco.com/t5/network-security/logging-pix-xlates/m-p/61569#M707780</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Has CISCO released a PIX Syslog Server that will run on Win2000 yet?  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, what level of logging are you doing to get this info?  &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Sep 2001 13:04:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/logging-pix-xlates/m-p/61569#M707780</guid>
      <dc:creator>thknight</dc:creator>
      <dc:date>2001-09-21T13:04:39Z</dc:date>
    </item>
    <item>
      <title>Re: Logging PIX xlates?</title>
      <link>https://community.cisco.com/t5/network-security/logging-pix-xlates/m-p/61570#M707781</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You would need to set the logging level to 6 to get translation messages.  If volumes are high keep an eye on memory and processor usage.  Logging at that level for long periods of time will kill the performance at peak periods.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Sep 2001 22:03:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/logging-pix-xlates/m-p/61570#M707781</guid>
      <dc:creator>thompson</dc:creator>
      <dc:date>2001-09-25T22:03:48Z</dc:date>
    </item>
    <item>
      <title>Re: Logging PIX xlates?</title>
      <link>https://community.cisco.com/t5/network-security/logging-pix-xlates/m-p/61571#M707782</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To my knowledge, Cisco does not have a Syslog server for Win2k at this time. However, you can obtain a very simple and free Syslog server from the following URL:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.boson.com/promo/utilities/syslog/syslog_utility.htm" target="_blank"&gt;http://www.boson.com/promo/utilities/syslog/syslog_utility.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By default, it listens to the local7 facility.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, I would really recommend you looking into having some type of linux based server.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Oct 2001 16:13:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/logging-pix-xlates/m-p/61571#M707782</guid>
      <dc:creator>mweddle</dc:creator>
      <dc:date>2001-10-04T16:13:04Z</dc:date>
    </item>
  </channel>
</rss>

