cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
558
Views
0
Helpful
4
Replies

Syslog configuration for our PIX 515e

mzamorano
Level 1
Level 1

I want to setup a server in our company so we can receive the logs from both or pix firewalls. I am not very satisfied with the documentation I found online. I would appretiate comments or advice as to how to set this up successfully?

Many thanks, Marcelo

4 Replies 4

paddyxdoyle
Level 6
Level 6

Marcelo,

Everything you need is in this document!

http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a0080094030.shtml

Have a look through and if you have any further questions give us a shout.

Rgds

PD

dgaunt
Level 1
Level 1

I think it should be added that if you do a Syslog over TCP, that the PIX will buffer the logs if the syslog server is down. This is good, unless the buffer gets to big, in which case the PIX will no longer accept new connections.

Is there a particular Syslog server that people prefer running with the PIX ? I have downloaded one (no names mentioned) but would prefer to find something that runs as a service rather than an application.

Any preferences ?

Hi,

I use usually two:

-Kiwi syslog (www.kiwisyslog.com) The freeware version is quite good, and you have a service version available. The commercial version adds some functionality (email alerts, filter by ip, etc) but the free one is quite good (and stable...)

-Ciscoworks VMS Security Monitor, if you have an IDS you have it... or with the full versions (20 or unlimited device). You can make reports and correlations.

Just take care that pixen are very "talkative" and send lots of messages, so on VMS, make sure you have a nice machine.

Regards

Review Cisco Networking for a $25 gift card