Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Search results for query: *

  1. agrigorof

    Please help me read this command/need to secure SMTP

    If you are using private IPs for the internal servers, that command by itself is not enough to allow inbound SMTP traffic. A "static" command is required as well to map the public IP to the private one. In order to tell what goes through and what doesn't we would need the entire configuration...
  2. agrigorof

    PIX 506 Report

    The "logging host" command seems incorrect - should be "logging host inside ip_address". There is no need to specify a port. The Pix firewall will use the default syslog port: UDP/514. Here is an example of logging setup for a PIX506: 1. Configure a syslog server. You can download the free Kiwi...
  3. agrigorof

    NS25 traffic report

    There is a better way of getting the Netscreen logs instead of copying them from the Netscreen management interface. See the second Q/A from here: http://www.eventid.net/firegen/fgnsfaq.asp Once you get the logs you can analyze them with your own custom tools or use a readily available log...
  4. agrigorof

    NS25 traffic report

    Do you need realtime data or traffic statistics for last x hours? Adrian Grigorof http://www.firegen.com FireGen Log Analyzers for Pix, Netscreen and SEF
  5. agrigorof

    PIX 506 Report

    See FireGen for Pix Log Analyzer: http://www.eventid.net/firegen/firegenpix2.asp Regards, Adrian
  6. agrigorof

    Very basic question on logs

    Here are practically what you need to do: 1. Configure a syslog server. You can download the free Kiwi Syslog server (www.kiwisyslog.com) and install it on any Windows NT/2000/XP/2003 machine. Let's say the IP address of the syslog server is 192.168.1.5 2. Configure Pix to send its logs to the...
  7. agrigorof

    Newbie logging question.

    Level 6 logging will provide you with all that you need. The rest depends on the reporting software. See these links: http://www.eventid.net/firegen/mildco01-2004-03-12-165112-ondemand.html and http://www.eventid.net/firegen/firegenpix2.asp for an example of what you can get from the Cisco...
  8. agrigorof

    Log levels tips

    The FAQ is already there. See http://www.eventid.net/firegen/fgpix2faq.asp Adrian Grigorof http://www.eventid.net/firegen/firegenpix2.asp FireGen for Pix Log Analyzer
  9. agrigorof

    SMTP Traffic Log

    Setting the logging level to 6 would enable the recording of the "Built..", "Teardown..." messages and those will capture any type of traffic, not only SMTP. See the following report obtained from a PIX firewall set to logging level 6...
  10. agrigorof

    Log Analyzer for PIX messages

    Actually, it does support the 6.3.x PIX firmware. The Firegen website did not keep up with the software :) Adrian Grigorof http://www.eventid.net/firegen/firegenpix2.asp FireGen for Pix Log Analyzer
  11. agrigorof

    Log Analyzer for PIX messages

    Sawmill is basically just a web traffic analyzer. The "firewall" analysis section is quite basic and there is hardly any value in that information. Just compare the sample reports: http://www.eventid.net/firegen/mildco01-2004-03-12-165112-ondemand.html vs...
  12. agrigorof

    telnetting to PIX 506

    No need to do that. Simply connect with a browser from behind that firewall to http://checkip.dyndns.org/ and you will see the public IP address used by the firewall. Adrian Grigorof http://www.eventid.net/firegen/firegenpix2.asp FireGen for Pix Log Analyzer
  13. agrigorof

    telnetting to PIX 506

    Obviously, you need to know the IP address or the host name of the firewall in order to connect with your VPN client. If the IP address is dynamically assigned, you may have to use a dynamic dns agent behind your firewall that could update the host name (and you would use that host name in your...
  14. agrigorof

    Log Analyzer or parser for Raptor ?

    FireGen is able to analyze your local logs. The log retrieval is optional. Send a short email to support@firegen.com if you need assistance in setting it up. Adrian Grigorof http://www.eventid.net/firegen/firegenpix2.asp FireGen for Pix Log Analyzer
  15. agrigorof

    telnetting to PIX 506

    If you cannot telnet to your firewall using just telnet 192.168.0.2 then most probably you have to enable telnet access for your workstation or it could be that there is no network connectivity between the firewall and your workstation. To enable telnet, connect to the firewall via the console...
  16. agrigorof

    Log Analyzer or parser for Raptor ?

    See FireGen for SEF/Raptor: http://www.eventid.net/firegen/firegensef.asp Regards, Adrian Grigorof
  17. agrigorof

    Log levels tips

    Silvia, Please email support@firegen.com for support on this issue - they are quite quick in answering. This forum might not be appropriate for a "how-to" on FireGen. I can assure you that you can analyze your own logs, not just the sample. Adrian Grigorof
  18. agrigorof

    Question about "IDS, DNS Attacks graph"

    Have you configured your firewall to report to a syslog server (i.e. Kiwi syslog)? If yes, parse those syslog servers and see the details about the IDS events. Use a log anlayzer (wink, wink) to look for the details that you are interested in. Adrian Grigorof...
  19. agrigorof

    Log Questions

    What protocols are used to connect to or from that IP address? Enable level 6 logging on your firewall for a day and see what internal user is connecting there and what protocols are used. Adrian Grigorof http://www.eventid.net/firegen/firegenpix2.asp FireGen for Pix Log Analyzer
  20. agrigorof

    Traffic Clogged

    Setup a syslog server (i.e. Kiwi Syslog), enable level 6 logging and see what is kind of traffic goes through the firewall. Adrian Grigorof http://www.eventid.net/firegen/firegenpix2.asp FireGen for Pix Log Analyzer

Part and Inventory Search

Back
Top