Posts

Showing posts with the label Kiwi SysLog

Logging PIX and Kiwi SysLog

Syslog daemons are little programs that listen to syslog messages coming over the network over port 514UDP. When a message gets logged in the application, the daemon dumps it in a text file or a database for later use. Archiving and backuping your log is very important: they can be very useful to help you diagnostic a security problem or help with a legal one. To get started, we need to enable logging in your firewall, to do this follow these steps: 1- Log into your firewall 2- Enter those commands: firewallname> enable [enter enable password] firewallname# conf t firewallname(config)# logging on firewallname(config)# logging trap debugging firewallname(config)# logging host inside [ip of your syslog server] firewallname(config)# write mem You may also need to configure your pix to send a timestamp along with each message if your syslog server doesn't generate one itself. The command to generate a timestamp is: firewallname(config)# logging timestamp In this case we won't...