List Info

Thread: PIX with Syslog




PIX with Syslog
user name
2005-12-19 13:02:20
Thanks Brain and Gray,
 
I configured my SysLog server over udp port 1058 instead TCP port 1058
 
Now its is woking preety good. Just configured it give me a day to monitor then i will give you all the correct respnse.
 
Thanks Alot Brain and Gray.
 
thanX
Chetan
 
----- Original Message -----
Sent: Monday, December 19, 2005 12:34 AM
Subject: [PIX_Firewall] Re: PIX with Syslog

chetanvatika,

So as Gary and I have both pointed out if you use TCP Syslog in the
PIX and the Syslog server doesn't acknowledge the Syslog messages back
to the PIX; the PIX will think the Syslog server is down and stop
creating new translations.  This means no new sessions can be created
by the PIX.  You can use the command "logging permit-hostdown" to make
the PIX with syslog set for TCP act the same as syslog set for UDP.

My recommendation is that unless you have a security policy that says
"if we can't log traffic, then we shouldn't pass traffic", you should
not use TCP syslog.  It uses more processor cycles on your PIX, it
creates more traffic, and you can accomplish the same thing using
syslog over UDP.

My guess is that your syslog server might be busy at that time of day
doing something that is scheduled (something other than Syslog).

Liberty for All,

Brian

--- In PIX_Firewall@yahoogroups.com, "chetanvatika"
<chetanvatikay...> wrote:
>;
> ThanKX Brain,
>;
> Syslog server is working&nbsp; preety good on tcp/1058.
>
> I am facing the problem that my pix works fine all day but when it
comes to night like aruond 6-7pm it stop creating new connections to
outside interface and i have to reeboot it.
>
> What can be the problem??
>
> Please help with this.
>
;  ----- Original Message -----
;  From: Brian
;  To: PIX_Firewall@yahoogroups.com
;  Sent: Friday, December 16, 2005 12:11 AM
>&nbsp;  Subject: [PIX_Firewall] Re: PIX with Syslog
>;
>
;  Sri,
>
;  Sure. ; Running PIX syslog over tcp/1058 should work.
>
;  You need to check to make sure that any personal firewall on the
>&nbsp;  syslog server allows that port. ; Some block high order tcp by default.
&gt;
;  You also have to remember that running syslog from PIX over TCP means
>  ; that if the server signals unavailable the PIX will stop forwarding
  traffic.
&gt;
;  If you want to debug you need to #1 make sure you can ping the syslog
>; &nbsp; server from the PIX and #2 find a ping tool that allows you modify the
>&nbsp;  port number and run it on a couple of PCs.
>
;  Liberty for All,
>
;  Brian
>
;  --- In PIX_Firewall@yahoogroups.com, "Sridhar M.N." <sridmobiley...>
&gt; &nbsp; wrote:
>; &nbsp; >
>&nbsp;   Hello Brian,
>; &nbsp; >   ;
;  >   The default for syslog is UPD 514, but TCP 1058 works great for
>&nbsp;  me. These are the settings I've enabled.
;  >   ;
;  >   logging host inside 10.1.30.48 tcp/1058
&gt; &nbsp; >   logging trap debugging
> &nbsp; >   logging on
>&nbsp;  > logging timestamp
> &nbsp; > logging standby
&gt; &nbsp; > logging buffered notifications
>&nbsp;  > logging history notifications
>&nbsp;  > logging facility 16
>&nbsp;  > logging queue 100
>&nbsp;  >   ;
;  >   In Kiwi setup, Under Inputs --> TCP, select Listen for TCP syslog
>; &nbsp; messages.
> &nbsp; >   TCP Port by default would be 1058
>&nbsp;   Bind to address --> Type in your system's IP address. In my case
>&nbsp;  its 10.1.30.48 and click OK
>&nbsp;  >   ;
;  >   I've attached the print screen of the kiwi setup too.
>&nbsp;  >
;  >
;  > Brian <brfordy...> wrote:
>; &nbsp; >   Sri, Chetan;
&gt; &nbsp; >
;  > The default port for Syslog is UDP 514.  If this configuration isn't
>  ; > working it is because either the PIX or the Syslog server is
sending /
>&nbsp;  > listening on the wrong port.
>  ; >
;  > Liberty for All,
>&nbsp;  >
;  > Brian
>  ; >
;  > --- In PIX_Firewall@yahoogroups.com, "Sridhar M.N."
<sridmobiley...>
&gt; &nbsp; > wrote:
>; &nbsp; > >
>&nbsp;  > > Hi Chetan,
&gt; &nbsp; > >   ;
;  > >   Issues these commands in your cisco pix.
>&nbsp;  > >   ;
;  > >   logging on
>&nbsp;  > > logging timestamp
> &nbsp; > > logging standby
&gt; &nbsp; > > logging buffered notifications
>&nbsp;  > > logging trap errors
>; &nbsp; > > logging history notifications
>&nbsp;  > > logging facility 16
>&nbsp;  > > logging queue 100
>&nbsp;  > > logging host inside ipaddress-of syslogd-server tcp/port-number
>&nbsp;  > >   ;
;  > >   example : logging host inside 10.1.2.5 tcp/1058
&gt; &nbsp; > >   ;
;  > >   1058 is the default port number and should work fine in KIWI
>&nbsp;  > syslog server. But make sure that KIWI is listening on port number
>; &nbsp; > 1058. Hope this helps.
;  > >
;  > > chetanvatika <chetanvatikay...> wrote:
>; &nbsp; > >   ; &nbsp;  font-face { &nbsp; font-family: Wingdings;  }  font-face { 
;  > font-family: Tahoma;&nbsp; }  page Section1 {size: 8.5in 11.0in; margin:
&gt; &nbsp; > 1.0in 1.25in 1.0in 1.25in; }  P.MsoNormal { &nbsp; FONT-SIZE: 12pt;
MARGIN:
>&nbsp;  > 0in 0in 0pt; FONT-FAMILY: "Times New Roman"&nbsp; }  LI.MsoNormal { 
;  > FONT-SIZE: 12pt; MARGIN: 0in 0in 0pt; FONT-FAMILY: "Times New
Roman"
;  > }  DIV.MsoNormal { &nbsp; FONT-SIZE: 12pt; MARGIN: 0in 0in 0pt;
>&nbsp;  > FONT-FAMILY: "Times New Roman"&nbsp; }  A:link { &nbsp; COLOR: blue;
>  ; > TEXT-DECORATION: underline&nbsp; }  SPAN.MsoHyperlink { &nbsp; COLOR: blue;
>  ; > TEXT-DECORATION: underline&nbsp; }  A:visited { &nbsp; COLOR: blue;
>  ; > TEXT-DECORATION: underline&nbsp; }  SPAN.MsoHyperlinkFollowed { &nbsp; COLOR:
>; &nbsp; > blue; TEXT-DECORATION: underline&nbsp; }  TT { &nbsp; FONT-FAMILY:
"Courier New"
>&nbsp;  > }  SPAN.EmailStyle18 { &nbsp; COLOR: navy; FONT-FAMILY: Arial ; }
;  > DIV.Section1 { &nbsp; page: Section1&nbsp; }  OL { &nbsp; MARGIN-BOTTOM: 0in  }
UL {
>&nbsp;  >   MARGIN-BOTTOM: 0in  } &nbsp; &nbsp;  Hi All,
>&nbsp;  > >   ;
;  > >   I installed KIWI syslogd on a computer .
>&nbsp;  > >   And configured the following command on PIX 506E but still its
>&nbsp;  > does not worked.
&gt; &nbsp; > >   indiapix# sh logging
&gt; &nbsp; > > Syslog logging: enabled
&gt; &nbsp; > >   ;  Facility: 20
>&nbsp;  > >   ;  Timestamp logging: disabled
&gt; &nbsp; > >   ;  Standby logging: disabled
&gt; &nbsp; > >   ;  Console logging: disabled
&gt; &nbsp; > >   ;  Monitor logging: disabled
&gt; &nbsp; > >   ;  Buffer logging: level debugging, 254617 messages logged
>; &nbsp; > >   ;  Trap logging: level emergencies, 140 messages logged
>; &nbsp; > >   ; &nbsp; &nbsp;  Logging to inside
;  > >   ;  History logging: disabled
&gt; &nbsp; > >   ;  Device ID: disabled
&gt; &nbsp; > >   ;
;  > >   When i do SH LOG on PIX it shows the log file but no entry had
>&nbsp;  > been done in Syslog server
>; &nbsp; > >   ;
;  > >   Please help me
;  > >   ;
;  > >   ;
;  > >   ;
;  > >   ;  ----- Original Message -----
;  > >   From: Bob Du Charme (bducharm)
;  > >   To: PIX_Firewall@yahoogroups.com
;  > >   Sent: Friday, December 02, 2005 6:45 AM
>&nbsp;  > >   Subject: RE: [PIX_Firewall] PIX with Syslog
>; &nbsp; > >  
;  > >
;  > >   Use an access-list to do this. Refer to
>&nbsp;  >
>&nbsp;
http://www.cisco.com/en/US/products/sw/secursw/ps2120/products_command_reference_chapter09186a00801727a3.html#wp1067755
  > for more details.
&gt; &nbsp; > >   ;
;  > >   Robert J. Du Charme, CCSP, ISSP, Cisco Systems
&gt; &nbsp; > > Security Training Manager
&gt; &nbsp; > > Critical Infrastructure Assurance Group (CIAG)
>; &nbsp; > > (v) 512.378.1063  (f) 512.378.1361
>&nbsp;  > > "Security Evangelist"
;  > >
;  > > http://www.cisco.com/go/ciag
&gt; &nbsp; > >
;  > >   ;
;  > >
;  > >   
;  > > ---------------------------------
;  > >   From: PIX_Firewall@yahoogroups.com
>; &nbsp; > [mailto:PIX_Firewall@yahoogroups.com] On Behalf Of chetanvatika
>&nbsp;  > > Sent: Wednesday, November 30, 2005 1:01 AM
>&nbsp;  > > To: PIX_Firewall@yahoogroups.com
>; &nbsp; > > Subject: Re: [PIX_Firewall] PIX with Syslog
>; &nbsp; > >
;  > >
;  > >  
;  > >   I tried doing this with Conduit but no sucess can anyone provide
&gt; &nbsp; > me the correct syntex for this prupose.
&gt; &nbsp; > >   ;
;  > >   ;  ----- Original Message -----
;  > >   From: Richards Aaron
;  > >   To: PIX_Firewall@yahoogroups.com
;  > >   Sent: Tuesday, November 29, 2005 7:27 PM
>&nbsp;  > >   Subject: RE: [PIX_Firewall] PIX with Syslog
>; &nbsp; > >  
;  > >
;  > >   ;  RDC? You mean RDP (Remote Desktop Protocol)? If you mean RDP,
>&nbsp;  > you need to allow port 3389 into your network from the outside
to the
>&nbsp;  > specific machine you want to allow access to. If you the
computer you
>&nbsp;  > will be coming from has a static IP, then you can also put that
in to
>&nbsp;  > lock it down more securely.
> &nbsp; > >   ;
;  > >   ;  Thank you,
>&nbsp;  > >   Aaron Richards
&gt; &nbsp; > >   Computer Specialist
  > >   Office of Inspector General
&gt; &nbsp; > >   Ext. 6378
>&nbsp;  > >
;  > >   -----Original Message-----
>&nbsp;  > > From: PIX_Firewall@yahoogroups.com
>; &nbsp; > [mailto:PIX_Firewall@yahoogroups.com] On Behalf Of ChetanVatika
>&nbsp;  > > Sent: Monday, November 28, 2005 11:50 PM
>&nbsp;  > > To: PIX_Firewall@yahoogroups.com
>; &nbsp; > > Subject: [PIX_Firewall] PIX with Syslog
>; &nbsp; > >   ;
;  > >   ;  Thank alot guys,
>  ; > >
;  > >   ;  I got a huge and heavy response in this group i will  like to
>&nbsp;  > thank all of the guys who help me setting up syslog server.
&gt; &nbsp; > >
;  > >   ;  Finally i used Kiwi syslog server.
&gt; &nbsp; > >
;  > >   ; &nbsp;
;  > >
;  > >   ;  I have a little problem going on with RDC in PIX
;  > >
;  > >   ;  I want to do RDC from outside interface to a machine in inside
>; &nbsp; > interface.
  > >
;  > >   ;  I Know i will get a quick and helfull reply in this group.
>; &nbsp; > >
;  > >   ; &nbsp;
;  > >
;  > >   ;  TAHNK U AlL,
>&nbsp;  > >
;  > >   ; &nbsp;
;  > >
;  > >   ;  bye Chetan
>; &nbsp; > >
;  > >   ; &nbsp;
;  > >
;  > >   ;
;  > >
;  > >
;  > >   
;  > > ---------------------------------
;  > >   YAHOO! GROUPS LINKS
;  > >
;  > >   
;  > >   ;  Visit your group "PIX_Firewall" on the web.
>&nbsp;  > >   
;  > >   ;  To unsubscribe from this group, send an email to:
>&nbsp;  > >  PIX_Firewall-unsubscribe@yahoogroups.com
&gt; &nbsp; > >   
;  > >   ;  Your use of Yahoo! Groups is subject to the Yahoo! Terms of
>&nbsp;  > Service.
;  > >
;  > >   
;  > > ---------------------------------
;  > >  
;  > >
;  > >
;  > >
;  > >   ; &nbsp; &nbsp; &nbsp; &nbsp;   ; &nbsp; &nbsp;
;  > > ---------------------------------
;  > > Yahoo! Shopping
&gt; &nbsp; > >  Find Great Deals on Holiday Gifts at Yahoo! Shopping
&gt; &nbsp; > >
>&nbsp;  >
;  >
;  >
;  >
;  >
;  >
;  >   
;  > ---------------------------------
;  >   YAHOO! GROUPS LINKS
;  >
;  >   
;  >   ;  Visit your group "PIX_Firewall" on the web.
>&nbsp;   
;  >   ;  To unsubscribe from this group, send an email to:
>&nbsp;  >  PIX_Firewall-unsubscribe@yahoogroups.com
&gt; &nbsp; >   
;  >   ;  Your use of Yahoo! Groups is subject to the Yahoo! Terms of
>&nbsp;  Service.
;  >
;  >   
;  > ---------------------------------
;  >  
;  >
;  >  
;  >
;  >
;  >
;  >   ; &nbsp; &nbsp; &nbsp; &nbsp;   ; &nbsp; &nbsp;
;  > ---------------------------------
;  > Yahoo! Shopping
&gt; &nbsp; >  Find Great Deals on Holiday Gifts at Yahoo! Shopping
&gt; &nbsp; >
>
>
>
>
>
>
>
------------------------------------------------------------------------------
&gt; &nbsp; YAHOO! GROUPS LINKS
>
; &nbsp;  a..  Visit your group "PIX_Firewall" on the web.
>&nbsp;   ; &nbsp;
; &nbsp;  b..  To unsubscribe from this group, send an email to:
>&nbsp; &nbsp;   PIX_Firewall-unsubscribe@yahoogroups.com
&gt; &nbsp; &nbsp; &nbsp;
; &nbsp;  c..  Your use of Yahoo! Groups is subject to the Yahoo! Terms of
Service.
>
>
>
------------------------------------------------------------------------------
&gt;





[1]

about | contact  Other archives ( Real Estate discussion Medical topics )