cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
4919
Views
0
Helpful
5
Replies

Cisco FTD / FDM Event Viewer or Realtime Monitoring

wcutajar
Level 1
Level 1

Hi I'm testing out a new FTD 1000 series and having a real hard time since i'm very used to ASA and ASDM.

 

I'm having an issue with Monitoring > Events which is always empty. I need to know what events are happening in realtime similar to "Monitoring > Logging > View on ASA but i'm unable to do so.

1 Accepted Solution

Accepted Solutions

@wcutajar 

On FDM navigate to Policies > Access Control. Then modify each Access Rule, click the "Logging" tab and then enable Logging, best practice is to enable at the End of the Connection. Save and deploy policy.

 

Example:-

 

22.PNG

View solution in original post

5 Replies 5

balaji.bandi
Hall of Fame
Hall of Fame

You need to enable Logging for the ACP to get the Logs (have you ?)

 

Make sure you configure - platform setting for Logs

 

FMC - Go to Policies-->Access-Policies

 

Select ACP  - use Logging ( depends on requirement)

 

image.png

 

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Unfortunately we're not using FMC, we're using FDM (Firepower Device Manager) to configure.

should be same i guess, never used FDM ( as per i know there is Limited features compare to FMC)

 

Look at the config guide : you may find some information

 

https://www.cisco.com/c/en/us/td/docs/security/firepower/660/fdm/fptd-fdm-config-guide-660.html

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

@wcutajar 

On FDM navigate to Policies > Access Control. Then modify each Access Rule, click the "Logging" tab and then enable Logging, best practice is to enable at the End of the Connection. Save and deploy policy.

 

Example:-

 

22.PNG

wcutajar
Level 1
Level 1

Awesome This worked thank you!

Review Cisco Networking products for a $25 gift card