Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
?
Solved

what's the best way to monitor the security logs of a PIX firewall?

Posted on 2004-11-04
9
Medium Priority
?
240 Views
Last Modified: 2010-04-17
I need to monitor a PIX firewall for any attempts to hack into our system, etc.  Mostly, just basic monitoring of the firewall to make sure that security is not breached.  Does anyone know of a good solution for doing this, preferably freeware?  I am relatively savvy with Cisco routers, but haven't dealt much with the PIX.  I would prefer something that integrates easily, has easy to read reports, and doesn't require much configuration of the firewall, on my part.  I know that I'm basically asking for a Cadillac for free, but maybe someone has some ideas.  My company is going through Sarbanes-Oxley auditing and I need to come up with some ideas relatively quickly.  Thanks in advance.
0
Comment
Question by:rhouston0872
  • 5
  • 4
9 Comments
 
LVL 79

Expert Comment

by:lrmoore
ID: 12498386
Easy enough to setup syslogging on the PIX to an inside host.
Then layer on any of several third pary syslot analysis packages:
http://www.surfstats.com/ciscopix_isa.asp  <== not free, but relatively inexpensive

Sawmill is another great option. Free for 30 days, and you might even qualify to keep using it for free:
http://www.sawmill.net/formats/PIX_Firewall_Syslog_Server_Format.html

Free Kiwi syslogger
http://www.kiwisyslog.com/info_syslog.htm

0
 

Author Comment

by:rhouston0872
ID: 12498705
Do you know where some directions are that would show me how to set up syslogging on the PIX?
0
 
LVL 79

Expert Comment

by:lrmoore
ID: 12498808
Sure:
http://www.cisco.com/en/US/products/sw/secursw/ps2120/products_command_reference_chapter09186a008010578b.html#wp1028090

Pretty simple, really:
   logging on
   logging host <ip address>
   logging trap informational

0
Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 

Author Comment

by:rhouston0872
ID: 12498860
Just one more question, if I may.  With this sort of logging, how is performance affected?
0
 
LVL 79

Expert Comment

by:lrmoore
ID: 12498907
Performance of the PIX is not affected at all.
Once you begin monitoring your logs, you can start pruning certain type messages out so that your log becomes more managable...

0
 
LVL 79

Expert Comment

by:lrmoore
ID: 12498933
Beware, though, that will this level of logging, depending on how many people you have using it, your log can grow to over 1GB per day! The logging host is the one that I would worry about performance on..

0
 

Author Comment

by:rhouston0872
ID: 12498968
Okay, thanks for your help.  It's much appreciated.
0
 

Author Comment

by:rhouston0872
ID: 12498990
I'm new to this, so I'm trying to figure out how to assign points.  Give me a minute.
0
 
LVL 79

Accepted Solution

by:
lrmoore earned 2000 total points
ID: 12498993
Not a problem. Simply choose the "Accept" button on any comment..

Thanks!
0

Featured Post

Keep up with what's happening at Experts Exchange!

Sign up to receive Decoded, a new monthly digest with product updates, feature release info, continuing education opportunities, and more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In this tutorial I will show you with short command examples how to obtain a packet footprint of all traffic flowing thru your Juniper device running ScreenOS. I do not know the exact firmware requirement, but I think the fprofile command is availab…
Shadow IT is coming out of the shadows as more businesses are choosing cloud-based applications. It is now a multi-cloud world for most organizations. Simultaneously, most businesses have yet to consolidate with one cloud provider or define an offic…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

578 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question