Firewall Wizards mailing list archives
Re: Syslog montioring and usage.
From: Ng Pheng Siong <ngps () netmemetic com>
Date: Wed, 14 Jul 2004 06:59:15 +0800
On Mon, Jul 12, 2004 at 01:54:07PM -0400, Chad Thomsen wrote:
I would like to better find out what the messages mean, and how to track down port scans, and other security related issues that syslog may reveal. To sum it up I want to be able to have a good understanding of a log file that comes form a Pix.
Your Cisco PIX docu set contains a PDF file entitled, "Cisco PIX Firewall System Log Messages." Check that out. On tracking down port scans, you may want to look at SnortSam and its PIX plugin. Essentially, SnortSam is a clone of Checkpoint FW-1's Suspicious Activity Monitor (SAM), wherein dynamic firewall rules may be created/destroyed in response to, um, suspicious activities. ;-) http://www.snortsam.net Cheers. -- Ng Pheng Siong <ngps () netmemetic com> http://firewall.rulemaker.net -+- Cisco PIX & Netscreen Config Version Control http://sandbox.rulemaker.net/ngps -+- M2Crypto, ZServerSSL for Zope, Blog _______________________________________________ firewall-wizards mailing list firewall-wizards () honor icsalabs com http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
Current thread:
- Syslog montioring and usage. Chad Thomsen (Jul 13)
- Re: Syslog montioring and usage. Chris Todd (Jul 15)
- Re: Syslog montioring and usage. Marcus J. Ranum (Jul 15)
- Re: Syslog montioring and usage. Josh Welch (Jul 15)
- Re: Syslog montioring and usage. Greg Skouby (Jul 15)
- Traffic generating tool survey David Lang (Jul 19)
- RE: Traffic generating tool survey lordchariot (Jul 19)
- Traffic generating tool survey David Lang (Jul 19)
- Re: Syslog montioring and usage. Ng Pheng Siong (Jul 15)
- Re: Syslog montioring and usage. Adrian Grigorof (Jul 19)
- <Possible follow-ups>
- RE: Syslog montioring and usage. Melson, Paul (Jul 15)
- RE: Syslog montioring and usage. Wes Noonan (Jul 19)
- RE: Syslog montioring and usage. Chad Thomsen (Jul 19)
- RE: Syslog montioring and usage. Wes Noonan (Jul 19)
- Re: Syslog montioring and usage. Roger Marquis (Jul 19)
- Re: Syslog montioring and usage. Brian Ford (Jul 19)