Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations derfloh on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

How do I log/audit URLs that passes thru the PIX?

Status
Not open for further replies.

dm318

MIS
Aug 4, 2002
35
SG
Hi Folks,

I need to log down Internet surfing activities on the PIX for my company. Could anyone direct me as to how I can do that? I'm currently relying on running "Logging Buffered Debugging", which I think is not the proper way to do this. Must I have an URL server or something like that? And if yes, any suggestion of a URL server software to log all the data?

A BIG thank you!
 
Go to
A good commercial tool is Security Reporter from NetIQ. Basically you need to log to a dedicated syslog server and use the tool to analyse the logs.

Be careful though, I remember an incident where our syslog server died and the PIX decided to stop all traffic because it couldn't find it!
 
If you use the 'allow' keyword at the end of your "filter url" config line it will allow all web access if the url server goes offline.

-gbiello
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top