<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Firewall Analyzer &amp; Reporter in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firewall-analyzer-reporter/m-p/1103524#M896293</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sushil,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i also need something to monitor  vpn usage.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 17 Sep 2008 12:20:33 GMT</pubDate>
    <dc:creator>francisco_1</dc:creator>
    <dc:date>2008-09-17T12:20:33Z</dc:date>
    <item>
      <title>Firewall Analyzer &amp; Reporter</title>
      <link>https://community.cisco.com/t5/network-security/firewall-analyzer-reporter/m-p/1103522#M896290</link>
      <description>&lt;P&gt;I am after a good Firewall Analyzer &amp;amp; Reporter for cisco PIX, ASA's. Dont mind open source. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to minitor the followings&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Traffic and Bandwidth Monitoring &lt;/P&gt;&lt;P&gt;Employee Internet Monitoring &lt;/P&gt;&lt;P&gt;Firewall Rules and URLs Monitoring &lt;/P&gt;&lt;P&gt;Firewall Alerts &amp;amp; Notifications &lt;/P&gt;&lt;P&gt;Firewall Alert Administration &lt;/P&gt;&lt;P&gt;Firewall Reports &lt;/P&gt;&lt;P&gt;VPN Reports &lt;/P&gt;&lt;P&gt;Proxy Server Reports &lt;/P&gt;&lt;P&gt;Network Security Reports &lt;/P&gt;&lt;P&gt;Custom Reports &lt;/P&gt;&lt;P&gt;Ad-hoc Reports &amp;amp; Scheduling Reports &lt;/P&gt;&lt;P&gt;Raw Log Search and Reports &lt;/P&gt;&lt;P&gt;Historical Trend Analysis &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 13:45:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-analyzer-reporter/m-p/1103522#M896290</guid>
      <dc:creator>francisco_1</dc:creator>
      <dc:date>2019-03-11T13:45:22Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall Analyzer &amp; Reporter</title>
      <link>https://community.cisco.com/t5/network-security/firewall-analyzer-reporter/m-p/1103523#M896291</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Syslog server could be:&lt;/P&gt;&lt;P&gt;- Kiwi Syslog:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.kiwisyslog.com/" target="_blank"&gt;http://www.kiwisyslog.com/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;- 30COM Deamon&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.ncat.co.uk/Download/" target="_blank"&gt;http://www.ncat.co.uk/Download/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;- There is also a Cisco Syslog Server which supports TCP Syslog 514 - pfss512.exe&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/cgi-bin/tablebuild.pl/pix?sort=release" target="_blank"&gt;http://www.cisco.com/cgi-bin/tablebuild.pl/pix?sort=release&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Commercial products that creates graphs and analyzes Syslog to generate stats could be:&lt;/P&gt;&lt;P&gt;- FireGen &lt;A class="jive-link-custom" href="http://www.eventid.net/firegen/" target="_blank"&gt;http://www.eventid.net/firegen/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;- Try this one FWLOGSUM (Freeware).&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.ginini.com/software/fwlogsum/" target="_blank"&gt;http://www.ginini.com/software/fwlogsum/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.ginini.com/software/fwlogsum/converters/" target="_blank"&gt;http://www.ginini.com/software/fwlogsum/converters/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;It uses basicly PERL scripts and supports a wide range of Firewalls. You just need to install Perl in your Windows environment.&lt;/P&gt;&lt;P&gt;- Try Sawmill (Eval version)&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.sawmill.net/" target="_blank"&gt;http://www.sawmill.net/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;- EIQ Networks Network Security Analyzer eiqnetworks.com&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that gives you some ideas what to try.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#############&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can opt for :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;MARS&lt;/P&gt;&lt;P&gt;HP OPENVIEW&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sushil&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Sep 2008 11:51:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-analyzer-reporter/m-p/1103523#M896291</guid>
      <dc:creator>suschoud</dc:creator>
      <dc:date>2008-09-17T11:51:00Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall Analyzer &amp; Reporter</title>
      <link>https://community.cisco.com/t5/network-security/firewall-analyzer-reporter/m-p/1103524#M896293</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sushil,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i also need something to monitor  vpn usage.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Sep 2008 12:20:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-analyzer-reporter/m-p/1103524#M896293</guid>
      <dc:creator>francisco_1</dc:creator>
      <dc:date>2008-09-17T12:20:33Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall Analyzer &amp; Reporter</title>
      <link>https://community.cisco.com/t5/network-security/firewall-analyzer-reporter/m-p/1103525#M896295</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Some info which might be helpful in ' monitoring VPN ':&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;How to monitor VPN sessions, and specific info ( ex: number of sessions, source of session ,date ,duration, bandwidth used etc. )&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Possible solutions :&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Included with Cisco Security Manager is an application called Performance Monitor, which supports the monitoring of remote-access and site-to-site VPNs. &lt;/P&gt;&lt;P&gt;Links: &lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Security Manager: &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/go/csmanager" target="_blank"&gt;http://www.cisco.com/go/csmanager&lt;/A&gt; &lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Performance Monitor User Guide: &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/ps6498/products_user_guide_book09186a00806b7a60.html" target="_blank"&gt;http://www.cisco.com/en/US/products/ps6498/products_user_guide_book09186a00806b7a60.html&lt;/A&gt; &lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Performance Monitor originates from the previous security managment product called CiscoWorks VMS and is currently not undergoing much further enhancement.&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Performance Monitor requires a different license file. For Security Manager 3.0, the license file is included on the DVD, but for 3.1 it is delivered via registering the included PAK on Cisco.com and receiving via email. The Performance Monitor license file is installed using the Common Services browser interface (not the Security Manager client). Click CiscoWorks in the upper right of the browser after logging in, then Common Services &amp;gt; Server &amp;gt; Admin &amp;gt; Licensing.&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) Open source tool which can be used :&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;   &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://cacti.net/" target="_blank"&gt;http://cacti.net/&lt;/A&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3) Using the ASDM --&amp;gt; Under monitoring, VPN statistics, Sessions you can filter by Remote Access, Site-to-Site, clientless SSL, SSL client or email proxy. Under Site-to-Site there are stats for connection/IP address, protocol/encryption, login time/duration and Bytes TX/RX &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do rate helpful posts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sushil&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Sep 2008 12:23:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-analyzer-reporter/m-p/1103525#M896295</guid>
      <dc:creator>suschoud</dc:creator>
      <dc:date>2008-09-17T12:23:10Z</dc:date>
    </item>
  </channel>
</rss>

