10-08-2024 11:26 AM
I've noticed in FMC that I can see traffic logged that traverses the FTD however traffic to the FTD is not logged. I am curious to see if someone is trying a port scan or something like that. So for example if my FTD interface is 192.168.0.1 and I try to telnet to 192.168.0.1 nothing is logged.
Is there a specific destination address or name that can be entered to see traffic that was destined to the FTD?
Thanks.
10-08-2024 11:28 AM
10-08-2024 07:35 PM
In addition to the syslog setup already mentioned in the earlier reply, note that Connection Events (or Unified Events) will generally only include connections handled by the Access Control Policy or Prefilter Policy.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide