cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3636
Views
0
Helpful
4
Replies

Firepower - Change Syslog port from default

gamoore
Level 1
Level 1

Hi,

 

For the Firepower v7.0 platform is it possible to change the Syslog forwarding port from default udp/514 to something else, for FMC, FTD, the Intrusion Policies?

4 Replies 4

Mark Elsen
Hall of Fame
Hall of Fame

 

 - FYI : https://support.auvik.com/hc/en-us/articles/360048078412-How-to-configure-syslog-on-Cisco-devices-with-Firepower-Management-Center

 M.



-- Let everything happen to you  
       Beauty and terror
      Just keep going    
       No feeling is final
Reiner Maria Rilke (1899)

For the FTD you can change the external Syslog server port through the Platform Setting policy, however, if you are trying to change the forwarding port of the FTD/IPS events to the FMC then in that case you would need to change the secure tunnel port on the FTD. The reason of this is because one of the reasons the FTD uses the secure tunnel port for is to send the connections, IPS, SSL etc events to the FMC. The command to change that port would be "configure network-management port ...".

Hi Aref,

 

I am trying to change the FTD/IPS events to an external Syslog Server on a port different from udp/514. Is this possible?

Hi, you can do that from the Platform Setting policy when you add the Syslog server in the Syslog Servers section, Step 3 in this guide:

Configure Logging on FTD via FMC - Cisco

Review Cisco Networking for a $25 gift card