cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2663
Views
0
Helpful
4
Replies

Firepower - Change Syslog port from default

gamoore
Level 1
Level 1

Hi,

 

For the Firepower v7.0 platform is it possible to change the Syslog forwarding port from default udp/514 to something else, for FMC, FTD, the Intrusion Policies?

4 Replies 4

marce1000
VIP
VIP

 

 - FYI : https://support.auvik.com/hc/en-us/articles/360048078412-How-to-configure-syslog-on-Cisco-devices-with-Firepower-Management-Center

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

For the FTD you can change the external Syslog server port through the Platform Setting policy, however, if you are trying to change the forwarding port of the FTD/IPS events to the FMC then in that case you would need to change the secure tunnel port on the FTD. The reason of this is because one of the reasons the FTD uses the secure tunnel port for is to send the connections, IPS, SSL etc events to the FMC. The command to change that port would be "configure network-management port ...".

Hi Aref,

 

I am trying to change the FTD/IPS events to an external Syslog Server on a port different from udp/514. Is this possible?

Hi, you can do that from the Platform Setting policy when you add the Syslog server in the Syslog Servers section, Step 3 in this guide:

Configure Logging on FTD via FMC - Cisco

Review Cisco Networking for a $25 gift card