cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
906
Views
0
Helpful
8
Replies

fmc syslog

shaikh.zaid22
Level 1
Level 1

hi,

i have ftd with fmc running 7.0.1, i have configured the syslog server to send the remote vpn syslogs to a NAC for posture and compliance check. Now the logs are showing up in the NAC, but, in encrypted format not in cleartext.

Kind assistance is required, if anybody knows how to send syslogs in cleartext to external syslog server from fmc.

 

8 Replies 8

marce1000
VIP
VIP

 

 - Are you sure this is not related to the NAC handling of the logs ?

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

balaji.bandi
Hall of Fame
Hall of Fame

what NAC here ?

how is your syslog config TCP or UDP ?

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Hi marce and balaji,

Yes it is a forescout NAC, we are configuring for VPN events and then apply compliance policy. However, the logs are not readable. I was wondering whether it is the job of the forescout parser or fmc is sending syslogs in unreadable format.

personally, never seen this issue before until we missing something here?

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

We are sending UDP 514 ports.

Syslog from the FMC should not be encrypted, Are you sure you are not using eStreamer?

--
Please remember to select a correct answer and rate helpful posts

We have Forescout NAC, wherein we are capturing VPN logs, which is not showing in plaintext.

That is a bit odd, you should be seeing the permit / deny logs received on the "inside" interfaces.  Do you have sysopt connection permit-vpn enabled?  If you have this enabled you could try disabling it, but then be aware that you need to configure access rules on the outside interface for the VPN traffic, and then enable syslog for those rules.

--
Please remember to select a correct answer and rate helpful posts
Review Cisco Networking for a $25 gift card