09-18-2024 01:40 PM
We detected traffic from an external malicious server targeting one of our sites through the firewall.
We would like to check whether there was any access to the Cisco SD-WAN Router from this source.
Is it possible to confirm traffic access logs (such as Source IP, Destination IP, Allowed or Denied) via vManage?
09-20-2024 05:17 AM
Hi,
in GUI Monitor>Logs can show this.
In "events" you can find logins for routers , in 'audit logs' you can find logins for vmanage
09-20-2024 12:22 PM
@Kanan Huseynli
Thank you very much!
Is it possible to confirm traffic access logs (such as Source IP, Destination IP, Allowed or Denied)?
I am thinking of firewall logs.
I would like to confirm if the logs show traffic flow from which source IP address to which destination IP address.
11-10-2024 06:08 AM
you want to troubleshouting or real time log ?
MHM
11-10-2024 06:17 AM
We detected traffic from an external malicious server targeting one of our sites through the firewall.
Is the Firewall front of any Edge router, how does your network Looks like.
Is the site have Internet breakout from your cEdge router ?
is the source ip behind cedge router ?
Yes if the Firewall able to log and retain the Logs, that is the best place look, Do you have any netflow enabled on sd-wan side to investigate this ?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide