cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
770
Views
2
Helpful
4
Replies

FireSIGHT reporting issue

Md.Jashim Uddin
Level 1
Level 1

Hi,

There is an active/Standby Firewall with Sourcefire. Firewall is working well with Failover. But there is no report showing in the FireSIGHT/Defense Center as well as no rule is executed.

Although

1.All license (Protect,Control,FIRESIGHT,AMP,URL) are installed to the sourcefire

2.Rules are created properly.

3.Logging is enabled.

4.Packets are being sent to Sourcefire.

4 Replies 4

Aastha Bhardwaj
Cisco Employee
Cisco Employee

Hi,

When you say report what exactly do you mean ? Try looking for Analysis >connection events , if you see the traffic from the active firewall ? Also check the access-list that you have pushed to the active FW does that have logging enabled on the rules ?

Regards,

Aastha Bhardwaj

Rate if that helps!!!

Thanks Aastha Bhardwaj,

There are two attached files. I think it will help you. Reporting means there is nothing in Analysis >connection events which is shown in the events_blank.png file.

Here is the Active Firewall Configuration

access-list ACL_ANY extended permit ip any any 

!

class-map SFR
match access-list ACL_ANY

!

policy-map global_policy

  class SFR
    sfr fail-open

!

Hi,

On the right hand top corner the time window that is there , can you change the time to say 1 day or 1 week and see if you see the connection events , currently it is set to 1 hr.

Regards,

Aastha Bhardwaj

Rate if that helps!!!

Thanks Aastha Bhardwaj,

After restating the Esxi, its OK now.

Review Cisco Networking for a $25 gift card