cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1603
Views
5
Helpful
6
Replies

Cisco FTD Various Logging Configuration Differences

peymansarayeli
Level 1
Level 1

Hi Guys, I hope you are doing fine.

 

I have a question regarding Logging configuration in FTD.

 

As you may have observed, in Policy section there are two possibilities where you can edit Loggings:

1- Policy > Access Control > Logging

2- In each specific Access Rule there is a Logging section between "Comments" and "Inspection"

 

I could not find any proper documents that explains these separate sections clearly. Could you please help me understand them and the differences between them?

Best,

Peyman

1 Accepted Solution

Accepted Solutions

In this video Alex covers Syslog events related to Intrusion, Connection, Security Intelligence, Malware/File, and Audit. TimeStamps: 0:00 - Intro / Covered Items 1:00 - Out of Scope Items 2:00 - What to Log & Where to Log It 3:00 - Demo Sequence / FMC Audit Events 10:25 - Malware & File Events ...
6 Replies 6

balaji.bandi
Hall of Fame
Hall of Fame

If you looking Logging for ACP basis, then you need to choose the below one : ( rather using main logging)

 

image.png

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Dear @balaji.bandi,

 

Thanks for your response.

 

Basically I want to to know what is the difference between Logging here:

 

1.png

 

and here:

2.png

Best

The main Logging to do with syslog

image.png

 

Settings for access control policy logging allow you to configure default syslog destinations and syslog alert for the current access control policy. The settings are applicable to the access control policy and all the included SSL, prefilter, and intrusion policies unless the syslog destination settings are explicitly overridden with custom settings in included rules and policies.

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Dear @balaji.bandi 

Thanks for your explanation.

 

Correct me if I am wrong; If we configure logging in the general page of ACP, it will be applied to all rules until we change logging configuration on a specific rule?

 

Best,

Peyman

Hi all,

 

I found this video very useful.

 

https://www.youtube.com/watch?v=q8zrQ-2PUXk

 

Thanks @balaji.bandi 

In this video Alex covers Syslog events related to Intrusion, Connection, Security Intelligence, Malware/File, and Audit. TimeStamps: 0:00 - Intro / Covered Items 1:00 - Out of Scope Items 2:00 - What to Log & Where to Log It 3:00 - Demo Sequence / FMC Audit Events 10:25 - Malware & File Events ...

Thank you for the feedback, yes about share related to your query, but you made it by now..

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Review Cisco Networking products for a $25 gift card