10-21-2022 05:03 AM
When configuring a remote server destination for syslog messages on Firepower chassis manager (or any UCS-like chassis for that matter), is it possible to send to another port other than 514? For example, UDP 5145 or something similar?
10-21-2022 05:08 AM
Hello,
check the thread linked below...
10-21-2022 05:10 AM
Thanks, but that thread is talking about the FMC and FTD. I'm talking about the Firepower chassis manager itself. They are different.
10-22-2022 01:04 AM
Hello,
sorry about that...my bad. I (think I) looked extensively at the documentation, there does not seem to be an option directly in the GUI. I wonder what happens if you change the port on the ASA directly:
logging trap x.x.x.x transport udp port 5145
Maybe that affects the FCM...
10-24-2022 05:19 AM
I checked the CLI and there doesn't appear to be a way to specify a different port other than 514. Cisco documentation states that the default is 514 but it doesn't mention that you are able to modify that setting.
10-24-2022 07:08 AM
10-24-2022 07:26 AM - edited 10-24-2022 07:27 AM
Georg, thanks.
But again, I think you are posting solutions that only apply to FTD or ASA. We already have the firewalls sending syslogs on a non-standard port like you have just described.
We are running FPR-9300 security modules that are installed in a physical Firepower chassis (basically like a UCS chassis). I'm looking for a way to configure a non-standard system logging port on the chassis itself (for logs generated by the physical chassis). At this point I'm fairly certain that what I am trying to do isn't supported.
10-24-2022 07:34 AM
Hello,
I think I did a quite extensive search but could not find a way to change the port for the FPR modules either. My idea was that maybe, if you change the logging port on the ASA, it would affect the FPR as well, which apparently is not the case, since you have already changed it on the ASA.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide