cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1766
Views
0
Helpful
0
Replies

RV042: Configure Syslog?

jwells113
Level 1
Level 1

Can someone explain how the RV042 decides what to send via syslog?

I've just installed a new RV042 (v3) with f/w updated to 4.0.3.03-tm. I added some UPnP forwards for remote access, as well as PPTP forwarding, and I want to log all failed and successful use of these forwards via syslog, plus any failed incoming connection attempts (i.e., to non-forwarded ports). I have no additional access rules defined. Under Log Setting I've enabled unauthorized attempts and all General Log options, though it's not clear whether these apply to syslog or not.

In terms of logging traffic I'm really only interested in the selected entries above, but the GUI help for syslog says "When this feature is enabled, the router will send all log activities, including every source/ destination IP address and service, to syslog server." However this does not seem to be the case. With syslog enabled in the RV042 (and entries logged via Kiwi Syslog) I see very few (though not zero) entries for incoming (WAN to LAN) traffic, but many entries for outgoing (LAN to WAN). (I also get a LOT of entries for PPTP GRE traffic, which I could live without.) In particular, I see no entries for the incoming remote access connections or traffic, or incoming failed connections, though I see many entries for the corresponding LAN to WAN replies.

Do I need to add "allow" access rules to log incoming connections and attempts (and if so, why am I getting some entries for incoming traffic without them)?

Thanks.

0 Replies 0
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: