[Okta Webinar] Learn how to a build a cloud-first strategyRegister Now

x
?
Solved

Newbie Need Some Help with configuring Cisco PIX

Posted on 2007-10-15
6
Medium Priority
?
274 Views
Last Modified: 2010-04-09
I am trying to setup my cisco pix 515e to send email alerts to members of my helpdesk whenever there is an attempted intrusion.
I am a newbie to cisco , so any help would be greatly appreciated.
0
Comment
Question by:AC-IS
  • 3
  • 2
6 Comments
 
LVL 32

Expert Comment

by:harbor235
ID: 20081280

Send the messages to a syslog server, You can then develop scripts or use some open source program
to send the emails.

Pix does not send alerts to email addresses

harbor235 :}
0
 
LVL 79

Expert Comment

by:lrmoore
ID: 20081764
What version PIX OS? ver 7.x and above only have a feature to send syslog messages via snmp.
0
 

Author Comment

by:AC-IS
ID: 20081813
It is running 6.3(5). Is there any other way to get the PIX to send alerts? 3rd Party or otherwise.
0
Big Data Means Big Business

In data-dependent industries like IT, finance, and healthcare, there’s a growing demand for qualified analysts to fill leadership roles. WGU’s MS in Data Analytics has IT certifications from Oracle and SAS built into its curriculum at a flat fee that could save you money.

 
LVL 79

Expert Comment

by:lrmoore
ID: 20081897
Like harbor235 noted, setup a syslog server like kiwi  http://www.kiwisyslog.com
export all syslogging to the kiwi server, and have kiwi send email alerts, filtered on those alerts that you want to trigger an email..

0
 

Author Comment

by:AC-IS
ID: 20086252
I looked all over "kiwisyslog.com" site, and found no information on how to install or configure this logger. Also is there anything special i need to setup in the PIX to allow it to send the log to the localhost?
0
 
LVL 79

Accepted Solution

by:
lrmoore earned 2000 total points
ID: 20086503
The syslog daemon is free. Download it, install it and read the help files. It's pretty simple to use.

On the PIX, setup logging:

logging on
logging timestamp
logging trap notification
logging host inside 192.168.122.150  <== ip address of syslog host

You can disable specific log messages when you see that you are getting too many of them in the logs and they don't really mean anything.

no logging message 313001
no logging message 710005
no logging message 400010
no logging message 400014
no logging message 400015


0

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

As managed cloud service providers, we often get asked to intervene when cloud deployments go awry. Attracted by apparent ease-of-use, flexibility and low computing costs, companies quickly adopt leading public cloud platforms such as Amazon Web Ser…
Considering cloud tradeoffs and determining the right mix for your organization.
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…
Suggested Courses
Course of the Month20 days, 6 hours left to enroll

872 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question