02-16-2005 03:48 PM - edited 03-09-2019 10:21 AM
I am wondering if it is possible to track IP addresses of computers on the Internet that make requests to a Web Server in the DMZ behind a PIX 515. When looking at the communication to the Web server, the request comes in as originating from the DMZ interface of the PIX. Is there a way to see what the external IP is that the PIX 515 DMZ interface is NAT ing and see this from the Web server?
02-23-2005 07:44 AM
You can place an IDS before the PIX and get these details.
02-23-2005 09:19 AM
You could use NTOP or send informational syslog infos to a syslog server and then filter that flat file for the information that you are interested in.
PIX settings:
fixup protocol http 80
logging on
logging timestamp
logging trap informational
logging facility 21
logging host inside 192.x.y.z
A good syslog (server) utility is:
FREE: http://www.kiwisyslog.com/
sincerely
Patrick
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide