01-28-2022 01:28 PM
Hi,
For the Firepower v7.0 platform is it possible to change the Syslog forwarding port from default udp/514 to something else, for FMC, FTD, the Intrusion Policies?
01-28-2022 11:05 PM
M.
01-29-2022 04:39 AM
For the FTD you can change the external Syslog server port through the Platform Setting policy, however, if you are trying to change the forwarding port of the FTD/IPS events to the FMC then in that case you would need to change the secure tunnel port on the FTD. The reason of this is because one of the reasons the FTD uses the secure tunnel port for is to send the connections, IPS, SSL etc events to the FMC. The command to change that port would be "configure network-management port ...".
02-01-2022 07:30 AM
Hi Aref,
I am trying to change the FTD/IPS events to an external Syslog Server on a port different from udp/514. Is this possible?
02-01-2022 08:53 AM
Hi, you can do that from the Platform Setting policy when you add the Syslog server in the Syslog Servers section, Step 3 in this guide:
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide