Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations IamaSherpa on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

PIX 515 Top Ten List?

Status
Not open for further replies.

mmcgurty

MIS
Jun 5, 2001
84
US
Is it possible to produce a Top Ten most visited sites or something like that from the PIX 515 PDM or CLI? I am running a PIX with OS 6.3(3) and PDM 3.0(1). I'm guessing I'll need something like ntop to do this, but wanted to check to make sure.
 
I don't think you'll be able to do this using the PIX alone. There are log anaylzers for the PIX logging format. Other than that and as you mentioned NTOP on a spanned port, I don't think you will be able to collect the info you are looking for.
 
I was afraid of that. I appreciate the quick reply. I think I'm going to log a Cisco TAC ticket to see, if I find out otherwise I'll post here how to do it.

Do you know if the PIX can import a list of sites to block by URL or IP?
 
No toptalkers list or likewise.
what you need is a syslog service running and logg level info, then some 3rd party reporting tool.
Cheapest are kiwisyslog and sawmill or rnr report gen for pix.
For more enterprise class there is netforensics and network intelligence

If you log a TAC case the later will be the reply.
Cisco works together with the former Privat-I now Network Intelligence.
 
I was told by a colleague that Linux Squid and Webalyzer might be the cheapest way to go on this. I appreciate all the replies to my question and the names of some software to do this. I really like that device from Network Intelligence, but that looks pretty costly. I'll be checking out Sawmill here shortly. I've used KiwiSyslogger and I'm not sure it will really do what we need or want it to do by itself. But I'll certainly look into that option as well.

Unrelated to my initial question. We are also looking at something to do Content Filtering. Websense is the obvious solution to this, but again looks very pricey. I'm hearing sites 1/2 the size of ours have been about $300,000 for first year implementation costs. I doubt this is a viable solution. Any ideas on low-cost content filtering solutions?
 
Can someone please send me a copy of pix pdm, I can't download it from Cisco.

Thank you
 
Linux Squid is what we use. It is GREAT for breaking down site visits.

Russmis:

PIX PDM is already on your PIX.

Goto your console, and conf t
http server enable
http location <your network> <subnet mask> inside

Computer/Network Technician
CCNA
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top