cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
123
Views
0
Helpful
1
Replies

Request for Cisco Secure Email Syslog Source IPs

aviv1
Community Member

Hello Cisco Support,

We are currently configuring Syslog forwarding from our Cisco Secure Email Cloud Gateway to our internal SOC / CrowdStrike NG-SIEM environment.

We need to configure our Cisco Firepower firewall to allow incoming Syslog traffic from Cisco Cloud to our internal Syslog collector.

Could you please provide the exact source IP address(es) / NAT Gateway IPs / Outbound VIPs that Cisco Secure Email will use when sending Syslog traffic from our ESA allocation?

We specifically need the IP addresses that should be configured as the source addresses in our firewall rule.

 

1 Reply 1

Based on my testing, its the "management interface", the same IP you connect to when you go to the gui. 

I created a log subscription pointed at fqdn that we host, set it for syslog on port 514 and then looked at the unified event viewer then looked at incoming 514 connections...