Solved

Firewall Syslogs Needed!

Posted on 2007-03-24
4
640 Views
Last Modified: 2012-05-05
I'm comparing syslog structure among popular firewall appliances for a high school project.

I would like samples of syslog logs (please change the IP's for security sake) and I only need a few lines.

I'm trying to prove or disprove if there is indeed an industry standard syslog format or if different mfg's customize thier own.

Also wondering if a Mfg will have different syslog structures among it's different models.

I've already proved that Netgear firewall appliances have varying syslog same structures.

Help a student please...
0
Comment
Question by:kvnsdr
  • 2
4 Comments
 
LVL 32

Assisted Solution

by:rsivanandan
rsivanandan earned 100 total points
Comment Utility
Go to www.cisco.com and search for 'syslog', you'll get a lot of entries for both routers and firewalls

Go to www.juniper.net and search for 'syslog' again.

Cheers,
Rajesh
0
 
LVL 1

Accepted Solution

by:
HarrisRP earned 400 total points
Comment Utility
<163>%PIX-3-106011: Deny inbound (No xlate) icmp src outside:PublicNAT dst outside:1.2.3.4 (type 8, code 0)

<165>%PIX-5-304001: 1.2.3.4 Accessed URL 1.2.3.4:/index.cfm?md=game&tmp=detail&navID=14&gameid=401

<189>38: 12w5d: %SYS-5-CONFIG_I: Configured from console by vty0 (1.2.3.4)

<187>21908: 13w5d: %SNMP-3-AUTHFAIL: Authentication failure for SNMP req from host 1.2.3.4

To account for word wrap, I put an extra line between the four lines I posted. If you need more, let me know.

--richard
0
 
LVL 1

Assisted Solution

by:HarrisRP
HarrisRP earned 400 total points
Comment Utility
Thought you might like to know what devices the messages came from:

1 & 2:  cisco PIX 501 firewall
3: HP 8150 printer
4: Cisco 3640 router

And here is one from a 3-com switch:
<191>community=monitor enterprise=1.3.6.1.2.1.11 enterprise_mib_name=snmp uptime=284925094 agent_ip=1.2.3.4 generic_num=2 specific_num=0 version=Ver1 generic_name="Link down" var01_oid=1.3.6.1.2.1.2.2.1.1.215 var01_value=215 var01_mib_name=ifIndex.215 var01_value=215 var02_oid=1.3.6.1.2.1.2.2.1.7.215 var02_value=1 var02_mib_name=ifAdminStatus.215 var02_mib_value=up var03_oid=1.3.6.1.2.1.2.2.1.8.215 var03_value=2 var03_mib_name=ifOperStatus.215 var03_mib_value=down

--richard
0
 
LVL 1

Author Comment

by:kvnsdr
Comment Utility
I have a Cisco PIX myself.

I would like something from other mfg's if possible, like SonicWall, etc...

Thanks for the help so far.
0

Featured Post

Do You Know the 4 Main Threat Actor Types?

Do you know the main threat actor types? Most attackers fall into one of four categories, each with their own favored tactics, techniques, and procedures.

Join & Write a Comment

In this tutorial I will show you with short command examples how to obtain a packet footprint of all traffic flowing thru your Juniper device running ScreenOS. I do not know the exact firmware requirement, but I think the fprofile command is availab…
I found an issue or “bug” in the SonicOS platform (the firmware controlling SonicWALL security appliances) that has to do with renaming Default Service Objects, which then causes a portion of the system to become uncontrollable and unstable. BACK…
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
This video shows how to remove a single email address from the Outlook 2010 Auto Suggestion memory. NOTE: For Outlook 2016 and 2013 perform the exact same steps. Open a new email: Click the New email button in Outlook. Start typing the address: …

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

13 Experts available now in Live!

Get 1:1 Help Now