cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1649
Views
1
Helpful
3
Replies

NAT logs on FTD managed by FMC

Does anyone know if and where there are NAT log files on the FTD?  I have been going through most of the log files in expert mode but have not been able to find anything related to NAT yet. @Marvin Rhoads @MHM Cisco World @Rob Ingram @Sheraz.Salim  Have any of you come across a log file where this is noted?

--
Please remember to select a correct answer and rate helpful posts
1 Accepted Solution

Accepted Solutions

@Marius Gunnerud In order to get the syslog you have to go/configure syslog in LINA. Is your FTD is managed through FMC if so yes in that case you can see the live-log or the syslog logs according to your FMC setting.

but coming back to your question in FTD Expert mode no you wont find the NAT logs.

 

A kind of similar question was ask Here might it help you

please do not forget to rate.

View solution in original post

3 Replies 3

@Marius Gunnerud In order to get the syslog you have to go/configure syslog in LINA. Is your FTD is managed through FMC if so yes in that case you can see the live-log or the syslog logs according to your FMC setting.

but coming back to your question in FTD Expert mode no you wont find the NAT logs.

 

A kind of similar question was ask Here might it help you

please do not forget to rate.

That is what I though, but was hoping there was someone out there that knows something that I do not.

The thing is that due to the amount that is being logged by FMC the traffic that I am looking for has been overwritten in FMC.  I only have the public IP and I need to find the internal IPs that were associated with that IP on a specific day.

--
Please remember to select a correct answer and rate helpful posts

Sorry @Marius Gunnerud, what I know is reflected in the other thread which @Sheraz.Salim linked. The NAT is part of the connection event which is stored in that Monetdb database table and not in any flat file (as far as I know).

In addition to syslog, you could also choose to send Netflow off to a collector / system like Secure Network Analytics. SNA has quite extensive data retention and could show you a NAT associated with a given connection or flow from days or weeks ago.

Review Cisco Networking for a $25 gift card