01-03-2023 09:32 AM
hi,
i have ftd with fmc running 7.0.1, i have configured the syslog server to send the remote vpn syslogs to a NAC for posture and compliance check. Now the logs are showing up in the NAC, but, in encrypted format not in cleartext.
Kind assistance is required, if anybody knows how to send syslogs in cleartext to external syslog server from fmc.
01-03-2023 10:14 AM
- Are you sure this is not related to the NAC handling of the logs ?
M.
01-03-2023 10:15 AM
what NAC here ?
how is your syslog config TCP or UDP ?
01-03-2023 10:28 AM
Hi marce and balaji,
Yes it is a forescout NAC, we are configuring for VPN events and then apply compliance policy. However, the logs are not readable. I was wondering whether it is the job of the forescout parser or fmc is sending syslogs in unreadable format.
01-04-2023 01:24 PM
personally, never seen this issue before until we missing something here?
01-03-2023 10:29 AM
We are sending UDP 514 ports.
01-04-2023 12:40 PM
Syslog from the FMC should not be encrypted, Are you sure you are not using eStreamer?
01-04-2023 08:11 PM
We have Forescout NAC, wherein we are capturing VPN logs, which is not showing in plaintext.
01-05-2023 12:24 AM
That is a bit odd, you should be seeing the permit / deny logs received on the "inside" interfaces. Do you have sysopt connection permit-vpn enabled? If you have this enabled you could try disabling it, but then be aware that you need to configure access rules on the outside interface for the VPN traffic, and then enable syslog for those rules.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide