<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FMC - Configuration Guides? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fmc-configuration-guides/m-p/3703912#M986788</link>
    <description>&lt;P&gt;I will definitely look at videos, I've configured our ACL to log syslog and event viewer. In the event viewer I can see the connections with block/allow action. Is it possible to log who connects to the VPN for example? I have enabled logging on those too but I only see "connections" not users etc.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 10 Sep 2018 11:59:32 GMT</pubDate>
    <dc:creator>EdholmR</dc:creator>
    <dc:date>2018-09-10T11:59:32Z</dc:date>
    <item>
      <title>FMC - Configuration Guides?</title>
      <link>https://community.cisco.com/t5/network-security/fmc-configuration-guides/m-p/3703794#M986786</link>
      <description>&lt;P&gt;Hey I was recently put in charge of our Firewall which I have very little knowledge of. We're using FMC and I need to setup logging (detect portscans/bad applications/system login attempts(ssh/web)) etc, I've been trying to google but I cant find anything useful.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've enabled logging on platform settings, and on our access-policies&amp;nbsp;but I cant see anything useful on our syslog server.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There are other stuff I need to configure as well for example AMP/IDS/IPS. Any useful material for this? Is there a paid course or webinar to learn FMC?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm bit lost and I would love to learn.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 16:13:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-configuration-guides/m-p/3703794#M986786</guid>
      <dc:creator>EdholmR</dc:creator>
      <dc:date>2020-02-21T16:13:06Z</dc:date>
    </item>
    <item>
      <title>Re: FMC - Configuration Guides?</title>
      <link>https://community.cisco.com/t5/network-security/fmc-configuration-guides/m-p/3703827#M986787</link>
      <description>&lt;P&gt;The configuration guides are all under the product support page for FMC:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/security/defense-center-virtual-appliance/tsd-products-support-series-home.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/security/defense-center-virtual-appliance/tsd-products-support-series-home.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Those can be a bit overwhelming. For more a a primer, I'd recommend looking at the free Cisco Live presentations. There are also some great videos (also free for streaming) at labminutes.com.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Generally speaking you will get better context for any events from FMC itself rather than an external syslog server (unless it's part of a SIEM that's also doing correlation). If the ACP rules are set to log you should see connection events (Allow, Block, etc.), intrusion events etc. in FMC.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Sep 2018 09:21:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-configuration-guides/m-p/3703827#M986787</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-09-10T09:21:57Z</dc:date>
    </item>
    <item>
      <title>Re: FMC - Configuration Guides?</title>
      <link>https://community.cisco.com/t5/network-security/fmc-configuration-guides/m-p/3703912#M986788</link>
      <description>&lt;P&gt;I will definitely look at videos, I've configured our ACL to log syslog and event viewer. In the event viewer I can see the connections with block/allow action. Is it possible to log who connects to the VPN for example? I have enabled logging on those too but I only see "connections" not users etc.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Sep 2018 11:59:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-configuration-guides/m-p/3703912#M986788</guid>
      <dc:creator>EdholmR</dc:creator>
      <dc:date>2018-09-10T11:59:32Z</dc:date>
    </item>
    <item>
      <title>Re: FMC - Configuration Guides?</title>
      <link>https://community.cisco.com/t5/network-security/fmc-configuration-guides/m-p/3704228#M986789</link>
      <description>&lt;P&gt;I'm not positive about the syslog entries for VPN logins, but there is a Dashboard you can use for VPN users. See Dashboard &amp;gt; Access Controlled User Statistics, VPN tab.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can also create reports of the data that's displayed using the Report Designer button on the top right of that dashboard.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Sep 2018 17:45:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-configuration-guides/m-p/3704228#M986789</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-09-10T17:45:46Z</dc:date>
    </item>
  </channel>
</rss>

