01-03-2005 05:55 PM - edited 03-09-2019 09:54 AM
Hi there,
My IDS in PIX receive Large ICMP Unreachable Packet,But Logging In terminal monitor shows nothing about IDS although it is already set to debugging mode. Tear down tcp connection 252 for outside xxx.xxx.xxx.xxx to inside xxx.xxx.xxx.xxx 2906 tcp fins, what thats mean? what is happening in this scenario...
Thanks For helping beginner
Tonny
Solved! Go to Solution.
01-03-2005 09:39 PM
hi,
Tear down message seems normal. It is a normal TCP termination message. About the IDS logging, could you setup a syslog server and send all messages to it. May be it will log the IDS messages.
BTW is IDS active?
Thanks
Nadeem
01-04-2005 09:21 AM
Hi,
This link is helpful.
http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_60/syslog/pixemint.htm
i think KIWI SYSLOG's default configuration should be fine
thanks
Nadeem
01-03-2005 09:39 PM
hi,
Tear down message seems normal. It is a normal TCP termination message. About the IDS logging, could you setup a syslog server and send all messages to it. May be it will log the IDS messages.
BTW is IDS active?
Thanks
Nadeem
01-03-2005 10:52 PM
Hi Nadeem,
yes, the IDS is active, i'm using telnet to view the syslog, actually i want to use kiwi syslog, but i have no idea how to configure it...if u don't mind, could you give an example how to configure pix to send syslog to Kiwi syslog and how to configure that kiwi...
Thank you very much
Tonny
01-04-2005 09:21 AM
Hi,
This link is helpful.
http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_60/syslog/pixemint.htm
i think KIWI SYSLOG's default configuration should be fine
thanks
Nadeem
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: