cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2228
Views
9
Helpful
11
Replies

NAT Translation in Cisco FMC

hadeelOth81
Level 1
Level 1

Hello all,

    I'm using cisco FMC 4600 to manage FTD cluster and I need to get NAT statistics and events. As which internal IPs have been translated to a certain NAT IP address. 

Is there a way to do that in FMC?

Thank you, 

Hadeel

 

2 Accepted Solutions

Accepted Solutions

as @Marvin Rhoads mentioned employing the Secure Network Analytics but not everyone can have Netflow tool in place. but to give you some visibility from FMC and see the connection events you can go to "Analysis"-->"Unified-Events" this will bring you the live connection feed what FMC receving from the FTD. on the search bar you can put in your FTD name and it will filter all the connection passing through from your firewall. here you can filter/fine tune what you want to see. 

again as said it will not give you exctaly what you looking for but it will give you some insight of the connection. or the otherway you can do it from "Analysis"---"Connection-Event"--->"Edit-Search"-->Connection-Event-->Device(here you put your device name) and it will display the history of connection event. Also here agian you can right click one of the tab and narrow down what you want to see.

 

please do not forget to rate.

View solution in original post

Definitely look at Unified Events. I had forgotten we can select the NAT IP (Source or destination) from among the displayed columns - it's not enabled by default but can be added. You can then drag the column to be next to the original source IP (among other customizations). Once you have a filtered view that suits you you can even download the events as a csv. See the following screen shot:

Unified EventsUnified Events

The only downside is that you are limited to the FMC's event storage capacity. Depending on your FMC and how many events it is logging that can be as little as less than 1 day. You can see the capacity in the Health Monitor as shown below - my lab FMCv has 19 days capacity but it is very lightly used.

FMC Health MonitorFMC Health Monitor

View solution in original post

11 Replies 11

Marvin Rhoads
Hall of Fame
Hall of Fame

Unfortunately that information is not stored within FMC. It can be retrieved in real time from the cluster members using "show xlate".

If that information is required for forensic or historical purposes, the only way I know to get it is to setup Netflow export to a collector (Such as Cisco Secure Network Analytics, formerly known as Stealthwatch). Cisco firewalls use NSEL (Netflow Secure event Logging) which captures both the original and translated address.

Thank you so much @Marvin Rhoads . 

as @Marvin Rhoads mentioned employing the Secure Network Analytics but not everyone can have Netflow tool in place. but to give you some visibility from FMC and see the connection events you can go to "Analysis"-->"Unified-Events" this will bring you the live connection feed what FMC receving from the FTD. on the search bar you can put in your FTD name and it will filter all the connection passing through from your firewall. here you can filter/fine tune what you want to see. 

again as said it will not give you exctaly what you looking for but it will give you some insight of the connection. or the otherway you can do it from "Analysis"---"Connection-Event"--->"Edit-Search"-->Connection-Event-->Device(here you put your device name) and it will display the history of connection event. Also here agian you can right click one of the tab and narrow down what you want to see.

 

please do not forget to rate.

Definitely look at Unified Events. I had forgotten we can select the NAT IP (Source or destination) from among the displayed columns - it's not enabled by default but can be added. You can then drag the column to be next to the original source IP (among other customizations). Once you have a filtered view that suits you you can even download the events as a csv. See the following screen shot:

Unified EventsUnified Events

The only downside is that you are limited to the FMC's event storage capacity. Depending on your FMC and how many events it is logging that can be as little as less than 1 day. You can see the capacity in the Health Monitor as shown below - my lab FMCv has 19 days capacity but it is very lightly used.

FMC Health MonitorFMC Health Monitor

@Marvin Rhoads  exactly, this is what I used in production network. Stealthwatch pricing was quite high and we were not able to match it so yes, this is what I am doing/using this for long time. @hadeelOth81 if you have budget go for netflow stealthwatch. but if you like me then this is only solution to keep us running unless we able to manage the big guys so spent more money on the tool we love.

please do not forget to rate.

I will check this feature update you today 

NO need more comment other answer You perfectly
thanks 
MHM 

toolseo818
Level 1
Level 1

Yes, there is a way to obtain NAT statistics and events in Cisco FMC (Firepower Management Center) for your FTD (Firepower Threat Defense) cluster. To view the NAT translations and associated events, you can follow these steps:

  1. Log in to your Cisco FMC web interface.
  2. Navigate to the "Analysis" tab in the top menu.
  3. Select "Events" from the drop-down menu.
  4. In the left-hand panel, under "Event Types," expand the "Network" section and choose "NAT Events."
  5. This will display the NAT events in the main window, showing the source IP, destination IP, and translated IP addresses involved in the NAT process.

To obtain specific information about internal IPs translated to a particular NAT IP address, you can use the search and filter options in Cisco FMC:

  1. On the "Events" page, use the search bar at the top to enter the desired NAT IP address.
  2. Press Enter or click the search icon.
  3. The search results will display the events where the specified NAT IP address is involved.

By analyzing the NAT events and associated data, you can determine which internal IPs have been translated to a certain NAT IP address within your FTD cluster.

Please note that the exact steps and options may vary slightly depending on the version of Cisco FMC you are using.

hadeelOth81
Level 1
Level 1

Thank you all, your solutions saved me for now, the only downside as Marvin mentioned FMC can save up to 2 days 6 hours 32 min

hadeelOth81_0-1685453490584.png

Much appreciate your help!!

 

Thanks

 

You can config the syslog and offload to external server.

Go to ACP--->select your interested policy--->Logging---->Default Syslog settings:

Logging.PNG

 

please do not forget to rate.

Thank you @Sheraz.Salim . I already configured external syslog server. 

Review Cisco Networking for a $25 gift card