cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
719
Views
2
Helpful
4
Replies

Can traffic access logs (src IP, dst IP, Allowed or Denied) be check?

We detected traffic from an external malicious server targeting one of our sites through the firewall.
We would like to check whether there was any access to the Cisco SD-WAN Router from this source.
Is it possible to confirm traffic access logs (such as Source IP, Destination IP, Allowed or Denied) via vManage?

4 Replies 4

Hi,

in GUI Monitor>Logs can show this.

In "events" you can find logins for routers , in 'audit logs' you can find logins for vmanage

HTH,
Please rate and mark as an accepted solution if you have found any of the information provided useful.

@Kanan Huseynli 
Thank you very much!
Is it possible to confirm traffic access logs (such as Source IP, Destination IP, Allowed or Denied)?
I am thinking of firewall logs.
I would like to confirm if the logs show traffic flow from which source IP address to which destination IP address.

you want to troubleshouting or real time log ?

MHM

balaji.bandi
Hall of Fame
Hall of Fame
We detected traffic from an external malicious server targeting one of our sites through the firewall.

Is the Firewall front of any Edge router, how does your network Looks like.

Is the site have Internet breakout from your cEdge router ?

is the source ip behind cedge router ?

Yes if the Firewall able to log and retain the Logs, that is the best place look, Do you have any netflow enabled on sd-wan side to investigate this ?

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help