Newbie question !!!
There is a Cisco PIX Firewall and a Cisco ACS already steup. I set up the Cisco Syslog server (PFSS) on a Win2K server. Now, when trying to configure PFSS all I could find as options were,
-d %_disk_full—the maximum percentage of how full the disk is that you allow the Windows NT system to reach before causing the PIX Firewall to stop transmissions. This is an integer value in the range of 1 to 100. The default is 90.
-t tcp_port—the port used by the Windows NT system to listen for TCP syslog messages, the default is 1468. If you specify another port, it must be in the range of 1024 to 65535.
-u udp_port—the port used by the Windows NT system to listen for UDP syslog messages, the default is 514. If you specify another port, it must be in the range of 1024 to 65535.
-e disk_empty_watch_timer—the duration in seconds that PFSS waits between checks to see if the disk partition is still empty. The default is 5 seconds, the range is any number greater than zero.
-f disk_full_watch_timer—the duration in seconds that PFSS waits between checks to see if the disk partition is still full. The default is 3 seconds, the range is any number greater than zero.
My question is where do I set the other options like,
emails to be sent when an activity is to occur. Are all those to be set on the PIX firewall itself,
I found some options that could be issued on the pix firewall,
logging host #.#.#.#
logging facility X
logging trap Y
clock set 13:18:00 Apr 25 1999
logging timestamp
no logging message 111005
Now, what about all the other options like being able to specify a particular message (something that I can specify) on the happening on a parituclar event.
Could someone please guide me. I am hoping for more configuration options.
Tutorials, How-tos, Links would be great as well.
Thanks a bunch.
There is a Cisco PIX Firewall and a Cisco ACS already steup. I set up the Cisco Syslog server (PFSS) on a Win2K server. Now, when trying to configure PFSS all I could find as options were,
-d %_disk_full—the maximum percentage of how full the disk is that you allow the Windows NT system to reach before causing the PIX Firewall to stop transmissions. This is an integer value in the range of 1 to 100. The default is 90.
-t tcp_port—the port used by the Windows NT system to listen for TCP syslog messages, the default is 1468. If you specify another port, it must be in the range of 1024 to 65535.
-u udp_port—the port used by the Windows NT system to listen for UDP syslog messages, the default is 514. If you specify another port, it must be in the range of 1024 to 65535.
-e disk_empty_watch_timer—the duration in seconds that PFSS waits between checks to see if the disk partition is still empty. The default is 5 seconds, the range is any number greater than zero.
-f disk_full_watch_timer—the duration in seconds that PFSS waits between checks to see if the disk partition is still full. The default is 3 seconds, the range is any number greater than zero.
My question is where do I set the other options like,
emails to be sent when an activity is to occur. Are all those to be set on the PIX firewall itself,
I found some options that could be issued on the pix firewall,
logging host #.#.#.#
logging facility X
logging trap Y
clock set 13:18:00 Apr 25 1999
logging timestamp
no logging message 111005
Now, what about all the other options like being able to specify a particular message (something that I can specify) on the happening on a parituclar event.
Could someone please guide me. I am hoping for more configuration options.
Tutorials, How-tos, Links would be great as well.
Thanks a bunch.