Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
Hi,Can anyone confirm fo me whether it's possible to send syslog messages from routers running IOS firewall feature set to CSM, so that the events appear in CSM Event Manager, similar to the way that ASA's do?I've setup one of my routers to do this a...
We have an ASA5585-X with SSP-10 module installed that we are testing. The firewall's outside interface is connected to the internet and has a public address. We have CSM 4.2 installed and are sending events from the IPS to it.After we configured the...
It would be GREAT to be able to do this for custom/scheduled reports, but as far as I know it isn't possible.Have you tried using Event Manager to do what you are asking?Go to Firewall Traffic Events->View Settings->Add->Source then add the IP you ar...
Hi,I'm not sure that I can really help you, but I can verify that on my CSM 4.5 server which is running normally, that service has a starup type of automatic and is in the "Started" state.You may want to check your system and application event logs t...
johnnylingo - did youresolve this problem - was it a hardware issue?I'm seeing the same on a standby supervisor 32 running a similar version of code to you - 12.2(33)SXH2a
Thanks for the replies.So if there was a DOS attack occurring on the outside interface (possibly saturating our internet link) and the DOS traffic was being dropped by the ACL, IPS would have no visibility of that??
Hi,I'm aware of that - we have the policy map configured.We're getting very few alerts from IPS - I was expecting more, as the outside interface has a public IP address and there are scans, probes etc happening all the time.Let me put my question a ...