cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1350
Views
0
Helpful
2
Replies

NAT Logging in Firepower 4110

Is there a way to configure FTD to write syslog messages for changes to the NAT table? We'd like to be able to find which device on our network did a thing based on reports sent from external sources, but we can't without having a record of which device was using which port at a specific time.

 

Thanks!

2 Replies 2

Abheesh Kumar
VIP Alumni
VIP Alumni
I don't think so there is an option to configure logging for NAT table, You can configure Syslog instead.

I considered that, but don't see any meaningful Syslog messages relating to NAT. The only NAT related messages I see are like this:

 

Feb 19 2019 10:22:06 firepower syslog-ng[2115]: Log statistics; processed='source(msgs)=2296389', processed='global(payload_reallocs)=2369603', processed='src.none()=0', stamp='src.none()=0', processed='global(internal_queue_length)=0', processed='global(msg_clones)=0', processed='destination(cron_destination)=2907', processed='src.internal(msgs#2)=15233', stamp='src.internal(msgs#2)=1550596326', processed='global(sdata_updates)=0', processed='destination(messages_destination)=1540934', processed='center(received)=2296389', processed='center(queued)=1543841'

 

That isn't particularly helpful, since it doesn't say what IP addresses are involved or anything. Do I need to change something to get the information I care about logged?

Review Cisco Networking products for a $25 gift card