cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
807
Views
1
Helpful
6
Replies

FTD 1140 Live monitoring

dimlia83
Level 1
Level 1

Hello everybody,

Recently we change ASA5510 with FMC and FTD 1140. I am disappointed by the fact that the new firewall does not have live monitoring. I remember with the ASA5510 in the monitoring, I just entered an IP and immediately saw everything related to that IP. Now, for example, I ping an interface of the Firewall that I deny icmp and I can't find any event anywhere that says there are continuous pings that I deny.

Please Help.

6 Replies 6

Thanks for your answer. From what I understand, it is not include this very useful tool that has live monitoring. cisco just made our life much more difficult to see something as simple as an IP reaching the firewall.

I Will check update you tonight.

MHM

I will check thanks for your time

You are right, the FMC is mainly a tool to manage lots of firewalls and do the security event processing. ASDM only had to show the events from a single firewall.

What could you do:

  1. the unified Event viewer under Analysis has a live view. It is not the real time view as in ASDM but it is quite powerful in filtering.
  2. set up a log server like Graylog or something similar. Then let the FTD log to this box (this config is done in the platform settings). These logs again will be “near real time”.
Review Cisco Networking for a $25 gift card