Velocity Reviews - Computer Hardware Reviews

Velocity Reviews > Newsgroups > Computing > Cisco > Cisco 2811 Syslog configuration problem

Reply
Thread Tools

Cisco 2811 Syslog configuration problem

 
 
pix help
Guest
Posts: n/a
 
      01-31-2007
Hello,

I am trying to pass syslog from outside interface to server that sits
behind pix firewall. Details as follows.

Cisco2811
192.168.1.1 (LAN)
255.255.255.0
Kiwi Syslog on UDP port 514


Cisco Pix
192.168.1.2 (Outside Interface)
192.168.150.1 (Inside Interface)
255.255.255.0


Syslog sitting on:
192.168.150.27
255.255.225.0


I setup the 2811 to pass the syslog to 192.168.1.2
Trying to get the Pix to route all inbound UPD 514 traffic from the
Cisco 2811 to 192.168.150.27. I would like to keep the outside Cisco
2811 traffic visable in the syslog so I can tell between Pix, 2811,
and VPN 2005 that is logging to..


Here is the deal. The syslog is listeniing on UDP 514. All other
network devices are
logging to this port. (VPN,PIX, 2950's, Aironet)The Cisco 2811 is
setup for logging but nothing
comes through on UDP 514. When I allow all UDP traffic from Cisco
2811
through Pix firewall to syslog it works. It would not be good to
allow
all UDP traffic. What gives here? Anyone with suggestion of feedback
on this? I researched and could not find anything helpful.

Thanks!

 
Reply With Quote
 
 
 
 
Walter Roberson
Guest
Posts: n/a
 
      01-31-2007
In article <(E-Mail Removed) .com>,
pix help <(E-Mail Removed)> wrote:
> I am trying to pass syslog from outside interface to server that sits
>behind pix firewall. Details as follows.


>Cisco2811
>192.168.1.1 (LAN)
>255.255.255.0
>Kiwi Syslog on UDP port 514


No, you cannot run Kiwi Syslog on the Cisco 2811. You can only
configure the 2811 to send syslog information to somewhere, and that
somewhere might happen to be running Kiwi Syslog.

>Cisco Pix
>192.168.1.2 (Outside Interface)
>192.168.150.1 (Inside Interface)
>255.255.255.0


>Syslog sitting on:
>192.168.150.27
>255.255.225.0


static(inside,outside) udp interface 514 192.168.150.27 514
access-list out2in permit udp host 192.168.1.1 interface outside eq 514
access-group out2in in interface outside
 
Reply With Quote
 
 
 
 
pix help
Guest
Posts: n/a
 
      01-31-2007
On Jan 31, 10:29 am, "pix help" <(E-Mail Removed)> wrote:
> Hello,
>
> I am trying to pass syslog from outside interface to server that sits
> behind pix firewall. Details as follows.
>
> Cisco2811
> 192.168.1.1 (LAN)
> 255.255.255.0
> Kiwi Syslog on UDP port 514
>
> Cisco Pix
> 192.168.1.2 (Outside Interface)
> 192.168.150.1 (Inside Interface)
> 255.255.255.0
>
> Syslog sitting on:
> 192.168.150.27
> 255.255.225.0
>
> I setup the 2811 to pass the syslog to 192.168.1.2
> Trying to get the Pix to route all inbound UPD 514 traffic from the
> Cisco 2811 to 192.168.150.27. I would like to keep the outside Cisco
> 2811 traffic visable in the syslog so I can tell between Pix, 2811,
> and VPN 2005 that is logging to..
>
> Here is the deal. The syslog is listeniing on UDP 514. All other
> network devices are
> logging to this port. (VPN,PIX, 2950's, Aironet)The Cisco 2811 is
> setup for logging but nothing
> comes through on UDP 514. When I allow all UDP traffic from Cisco
> 2811
> through Pix firewall to syslog it works. It would not be good to
> allow
> all UDP traffic. What gives here? Anyone with suggestion of feedback
> on this? I researched and could not find anything helpful.
>
> Thanks!


Update the syslog is sitting on server behind Pix. Still cant log from
2811 to syslog server behind pix. Any help appreciated.

 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
2811 cisco router configuration ned help cannot connect to internet geneveve Cisco 1 12-29-2008 06:15 AM
Dial Up Configuration on Cisco 2811 with NM-2AM Module sultaans Cisco 0 10-17-2007 06:02 AM
perl 5.8.8 make test hangs on ext/Sys/Syslog/t/syslog................... indefinitely Bad Dog Perl Misc 0 08-09-2007 04:47 PM
is there any API available to implement Syslog server using Java (to capture all syslog messages - UDP protocol, port 514)? santa19992000@yahoo.com Java 2 06-20-2006 12:54 PM
Syslog replay script for centralized syslog host leroy isaac Perl Misc 1 10-29-2004 04:23 AM



Advertisments