
ManageEngine Firewall Analyzer :: User Guide
261
Zoho Corp.
Cisco PIX Firewall Reports
1. I am not seeing Traffic reports in Cisco firewall's?
1. In your Cisco PIX command line interface execute the command show
logging and check the trap logging value.
2. The trap logging should be set to informational for traffic logs to be
generated from Cisco PIX firewall's Execute the command logging trap
informational to set the trap logging to informational.
3. Ensure that no logs are disabled in Cisco PIX by executing the command
show logging disabled
4. Commonly, logs with id 302013,302014,302015 and 302016 are dealing
with traffic. Make sure those ids are not disabled in your cisco firewall. If
they are disabled then execute the command logging message to enable
them.
2. I am not getting VPN reports for Cisco firewall's?
We can setup two kind of VPN's in Cisco firewall's as below.
1. Remote Host VPN:
This is between a User PC and the Cisco firewall's. User PC could be
anywhere in the Internet. There are various technologies used to
accomplish the same. Firewall Analyzer supports the following types.
o IpSec:
Firewall Analyzer supports IpSec remote host vpn in Cisco firewall's.
Following are the sample logs generated:
Cisco PIX:
20_12_2005_09_00_20:<166>Dec 20 2005 09:52:14: %PIX-6-
109005: Authentication succeeded for user 'john' from
xxx.xxx.xxx.xxx/0 to xxx.xxx.xxx.xxx/0 on interface outside
20_12_2005_09_00_20:<166>Dec 20 2005 09:52:16: %PIX-6-
602301: sa created, (sa) sa_dest= xxx.xxx.xxx.xxx, sa_prot= 50,
sa_spi= 0x1e01c9b1(503433649), sa_trans= esp-3des esp-md5-hmac
, sa_conn_id= 46
20_12_2005_09_00_20:<166>Dec 20 2005 09:52:16: %PIX-6-
602301: sa created, (sa) sa_dest= xxx.xxx.xxx.xxx, sa_prot= 50,
sa_spi= 0x94e99fdc(2498338780),V sa_trans= esp-3des esp-md5-
hmac , sa_conn_id= 45
20_12_2005_09_00_20:<166>Dec 20 2005 09:55:24: %PIX-6-
602302: deleting SA, (sa) sa_dest= xxx.xxx.xxx.xxx, sa_prot= 50,
sa_spi= 0x1e01c9b1(503433649), sa_trans= esp-3des esp-md5-hmac
, sa_conn_id= 46
20_12_2005_09_00_20:<166>Dec 20 2005 09:55:24: %PIX-6-
602302: deleting SA, (sa) sa_dest= xxx.xxx.xxx.xxx, sa_prot= 50,
Komentarze do niniejszej Instrukcji