Solved

Firewall Syslogs Needed!

Posted on 2007-03-24
4
647 Views
Last Modified: 2012-05-05
I'm comparing syslog structure among popular firewall appliances for a high school project.

I would like samples of syslog logs (please change the IP's for security sake) and I only need a few lines.

I'm trying to prove or disprove if there is indeed an industry standard syslog format or if different mfg's customize thier own.

Also wondering if a Mfg will have different syslog structures among it's different models.

I've already proved that Netgear firewall appliances have varying syslog same structures.

Help a student please...
0
Comment
Question by:kvnsdr
  • 2
4 Comments
 
LVL 32

Assisted Solution

by:rsivanandan
rsivanandan earned 100 total points
ID: 18787208
Go to www.cisco.com and search for 'syslog', you'll get a lot of entries for both routers and firewalls

Go to www.juniper.net and search for 'syslog' again.

Cheers,
Rajesh
0
 
LVL 1

Accepted Solution

by:
HarrisRP earned 400 total points
ID: 18805152
<163>%PIX-3-106011: Deny inbound (No xlate) icmp src outside:PublicNAT dst outside:1.2.3.4 (type 8, code 0)

<165>%PIX-5-304001: 1.2.3.4 Accessed URL 1.2.3.4:/index.cfm?md=game&tmp=detail&navID=14&gameid=401

<189>38: 12w5d: %SYS-5-CONFIG_I: Configured from console by vty0 (1.2.3.4)

<187>21908: 13w5d: %SNMP-3-AUTHFAIL: Authentication failure for SNMP req from host 1.2.3.4

To account for word wrap, I put an extra line between the four lines I posted. If you need more, let me know.

--richard
0
 
LVL 1

Assisted Solution

by:HarrisRP
HarrisRP earned 400 total points
ID: 18805187
Thought you might like to know what devices the messages came from:

1 & 2:  cisco PIX 501 firewall
3: HP 8150 printer
4: Cisco 3640 router

And here is one from a 3-com switch:
<191>community=monitor enterprise=1.3.6.1.2.1.11 enterprise_mib_name=snmp uptime=284925094 agent_ip=1.2.3.4 generic_num=2 specific_num=0 version=Ver1 generic_name="Link down" var01_oid=1.3.6.1.2.1.2.2.1.1.215 var01_value=215 var01_mib_name=ifIndex.215 var01_value=215 var02_oid=1.3.6.1.2.1.2.2.1.7.215 var02_value=1 var02_mib_name=ifAdminStatus.215 var02_mib_value=up var03_oid=1.3.6.1.2.1.2.2.1.8.215 var03_value=2 var03_mib_name=ifOperStatus.215 var03_mib_value=down

--richard
0
 
LVL 1

Author Comment

by:kvnsdr
ID: 18805447
I have a Cisco PIX myself.

I would like something from other mfg's if possible, like SonicWall, etc...

Thanks for the help so far.
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Occasionally, we encounter connectivity issues that appear to be isolated to cable internet service.  The issues we typically encountered were reset errors within Internet Explorer when accessing web sites or continually dropped or failing VPN conne…
Imagine you have a shopping list of items you need to get at the grocery store. You have two options: A. Take one trip to the grocery store and get everything you need for the week, or B. Take multiple trips, buying an item at a time, to achieve t…
Migrating to Microsoft Office 365 is becoming increasingly popular for organizations both large and small. If you have made the leap to Microsoft’s cloud platform, you know that you will need to create a corporate email signature for your Office 365…
In this video I am going to show you how to back up and restore Office 365 mailboxes using CodeTwo Backup for Office 365. Learn more about the tool used in this video here: http://www.codetwo.com/backup-for-office-365/ (http://www.codetwo.com/ba…

867 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

16 Experts available now in Live!

Get 1:1 Help Now