cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
506
Views
0
Helpful
1
Replies

help with new ips config

ramccutc
Level 1
Level 1

I'm new to the IPS/ASA and looking for more information on IPS event log monitoring. I have the VMS software and I am looking into configuring a syslog server to capture events. We are a fairly small network (50-60 nodes) with only 3-4 cisco devices on the system. Do I need a dedicated syslog machine, what metrics do you look at when assigning machine roles?

1 Reply 1

globalnettech
Level 5
Level 5

Hello,

with only 4 devices, you could use your workstation as the syslog server, but that depends on how your network is being monitored. In a 24x7 operations center, you would definitely need a dedicated server, but if you alone are responsible, logging to your workstation should be sufficient.

Not sure what you mean by metrics, but regarding configuring traps and events on the IPS, have a look at this document:

Configuring the Cisco Intrusion Prevention System Sensor Using the Command Line Interface 5.1

Configuring SNMP

http://www.cisco.com/en/US/products/hw/vpndevc/ps4077/products_configuration_guide_chapter09186a008055df87.html

HTH,

GNT

Review Cisco Networking for a $25 gift card