
9-39
Cisco PIX Firewall and VPN Configuration Guide
78-15033-01
Chapter 9 Accessing and Monitoring PIX Firewall
Using Syslog
Managing IDS Syslog Messages
PIX Firewall lists single-packet (atomic) Cisco Intrusion Detection System (IDS) signature messages via
syslog. Refer to Cisco PIX
Firewall System Log Messages for a list of the supported messages. You can
view this document online at the following website:
http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_sw/v_63/63syslog/index.htm
All signature messages are not supported by PIX Firewall in this release. IDS syslog messages all start
with PIX-4-4000nn and have the following format:
%PIX-4-4000nn IDS:sig_num sig_msg from ip_addr to ip_addr on interface int_name
For example:
%PIX-4-400013 IDS:2003 ICMP redirect from 10.4.1.2 to 10.2.1.1 on interface dmz
%PIX-4-400032 IDS:4051 UDP Snork attack from 10.1.1.1 to 192.168.1.1 on interface outside
Note Cisco IDS signature number 1101 is not supported by PIX Firewall. When an unsupported signature
number is entered, PIX Firewall returns an error message.
Table 9-6 lists the values and the meaning of each syslog output parameter.
Ta b l e 9-6 Syslog Output Values
Syslog Value Meaning
sig_num
The signature number. Refer to the Cisco Secure
Intrusion Detection System Version 2.2.1 User
Guide for more information. You can view the
“NSDB and Signatures” chapter from this guide at
the following website:
http://www.cisco.com/univercd/cc/td/doc/product
/iaabu/csids/csids1/csidsug/sigs.htm
sig_msg
The signature message—approximately the same
as the NetRanger signature message.
ip_addr
The local to remote address to which the signature
applies.
int_name
The name of the interface on which the signature
originated.
<nnn> Displays the number of times this flow was permitted or denied by the ACL
entry in the configured time interval. The value is 1 when the first syslog
message is generated for the flow.
first hit Displays the first message generated for this flow.
n-second interval Displays the interval over which the hit count is accumulated.
Table 9-5 Syslog Message Format for ACL Logging
Field Description
Comentarios a estos manuales