06-11-2010 04:35 PM - edited 03-11-2019 10:58 AM
I have a Cisco PIX Firewall 525 Version 6.3(5) running that we are in process of decomissioning it. I am still getting some hitcounts on the following access-list and and want to anaylze it by sending it to syslog server.
access-list PeopleSupport line 21 permit ip host 10.71.0.170 172.29.136.0 255.255.255.0
access-list PeopleSupport line 24 permit ip host 10.71.0.170 172.22.195.0 255.255.255.0
access-list PeopleSupport line 31 permit ip host 10.110.9.171 172.16.152.0 255.255.255.0
access-list PeopleSupport line 26 permit ip host 10.71.0.170 172.22.199.0 255.255.255.0
I have enabled logging with following commands:
Logging on
Logging trap informational
Logging facility 6
Logging host inside 10.88.169.58
Now, What do I need to define in access-lists to send hit counts to syslog.
Will the below configuration work? I have a long list of access-list but only want to add logging to the above access-list Line Numbers.
From:
no access-list PeopleSupport line 21 permit ip host 10.71.0.170 172.29.136.0 255.255.255.0
no access-list PeopleSupport line 24 permit ip host 10.71.0.170 172.22.195.0 255.255.255.0
no access-list PeopleSupport line 31 permit ip host 10.110.9.171 172.16.152.0 255.255.255.0
no access-list PeopleSupport line 26 permit ip host 10.71.0.170 172.22.199.0 255.255.255.0
To:
access-list PeopleSupport line 21 permit ip host 10.71.0.170 172.29.136.0 255.255.255.0 log informational
access-list PeopleSupport line 24 permit ip host 10.71.0.170 172.22.195.0 255.255.255.0 log informational
access-list PeopleSupport line 31 permit ip host 10.110.9.171 172.16.152.0 255.255.255.0 log informational
access-list PeopleSupport line 26 permit ip host 10.71.0.170 172.22.199.0 255.255.255.0 log informational
06-11-2010 10:02 PM
Yes, That configuration should log infomrational messages to syslog for those access-list.
Here is your document reference :
http://www.cisco.com/en/US/docs/security/pix/pix63/system/message/pixemint.html#wp1029160
http://www.cisco.com/en/US/docs/security/pix/pix63/command/reference/ab.html#wp1067755
Regards,
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide