Logging Severity Levels

Logging Severity Levels
Level Numeric Code System Condition
Emergency 0 System unusable message
Alert 1 Take immediate action
Critical 2 Critical condition
Error 3 Error message
Warning 4 Warning message
Notification 5 Normal but significant condition
Informational 6 Information message
Debug 7 Debug message, log FTP commands, and WWW URLs
Foundation Summary 265
System log messages received at a syslog server begin with a percent sign (%) and are
structured as follows:
%PIX-level-message_number: message_text
You can set the level with the logging command so that you can view syslog messages on the
Security Appliance console, from a syslog server, or with SNMP.

PIX Firewall Syslog Server

PIX Firewall Syslog Server
PIX Firewall Syslog Server (PFSS) lets you view PIX Firewall event information from a
Windows NT system. It includes special features not found on other syslog servers:
■ The ability to receive syslog messages by TCP or UDP
■ Full reliability, because messages can be sent using TCP
PFSS can receive syslog messages from up to ten PIX units. You can install this product for
use with any model of Cisco PIX Firewall. If you have specified that the PIX send syslog
messages using TCP, the Windows NT disk might become full and the PIX unit stops its
traffic. If the Windows NT file system is full, the Windows system beeps, and the PFSS
disables all TCP connections from the PIX unit(s) by closing its TCP listen socket. The PIX
tries to reconnect to the PFSS five times, and during the retry it stops all new connections
through the PIX.
NOTE PFSS does not support the ASA Security Appliance.

Configuring a Syslogd Server

Configuring a Syslogd Server
Because syslogd was originally a UNIX concept, the features available in the syslogd
products on non-UNIX systems depend on the vendor implementation. Features might
include dividing incoming messages by facility or debug level or both, resolving the names of
the sending devices, and reporting facilities. For information on configuring the non-UNIX
syslog server, refer to the vendor’s documentation.
To configure syslog on UNIX, follow these steps:
Step 1 On SunOS, AIX, HPUX, or Solaris, as root, make a backup of the /etc/
syslog.conf file before modifying it.
Step 2 Modify /etc/syslog.conf to tell the UNIX system how to sort out the
syslog messages coming in from the sending devices—that is, which
logging-facility.level goes in which file. Make sure there is a tab between
the logging-facility.level and file-name.
Step 3 Make sure the destination file exists and is writable.
Step 4 The #Comment section at the beginning of syslog.conf usually explains
the syntax for the UNIX system.
Step 5 Do not put file information in the ifdef section.
Step 6 As root, restart syslogd to pick up changes.
For example, if /etc/syslog.conf is set for
local7.warn /var/log/local7.warn
warning, error, critical, alert, and emergency messages coming in on the local7 logging
facility are logged in the local7.warn file. Notification, informational, and debug messages
coming in on the local7 facility are not logged anywhere.
NOTE Configuring the syslog server is not covered on the PIX CSPFA 642-522 exam.
Configuring a Syslogd Server 263
If /etc/syslog.conf is set for
*.debug /var/log/all.debug
all message levels from all logging facilities go to this file.

Configuring SNMP Traps and SNMP Requests

Configuring SNMP Traps and SNMP Requests
SNMP requests can be used to query the Security Appliance on its system status information.
If you want to send only the cold start, link up, and link down generic traps, no further
configuration is required. SNMP traps send information about a particular event only when
the configured threshold is reached.
To configure a Security Appliance to receive SNMP requests from a management station, you
must do the following:
■ Configure the IP address of the SNMP management station with the snmp-server host
command.
■ Set the snmp-server options for location, contact, and the community password as
required.
To configure SNMP traps on the PIX, you must do the following:
■ Configure the IP address of the SNMP management station with the snmp-server host
command.
■ Set the snmp-server options for location, contact, and the community password as
required.
■ Set the trap with the snmp-server enable traps command.
■ Set the logging level with the logging history command.

Configuring the Cisco Security Appliance to Send Syslog Messages to a Log Server

Configuring the Cisco Security Appliance to Send Syslog Messages to a Log
Server
Configuring a Security Appliance to send logging information to a server helps you collect
and maintain data that can later be used for forensic and data traffic analysis. The Security
Appliance syslog messages are usually sent to a syslog server or servers. The Security
Appliance uses UDP port 514 by default to send syslog messages to a syslog server. The
syntax for configuring the Security Appliance Firewall to send syslog messages to a syslog
server is as follows:
Pixfirewall(config)#Logging host [interface] ip_address [tcp[/port] | udp[/port]]
[format emblem]
The variables [interface] and ip-address are replaced with the name of the interface on which
the syslog resides and the Internet Protocol (IP) address of the syslog server, respectively. The
Cisco Security Appliance supports the EMBLEM format. EMBLEM syslog format is designed
to be consistent with the Cisco IOS Software format and is more compatible with CiscoWorks
management applications, such as Resource Manager Essentials (RME) syslog analyzer. Use
the option format emblem to send messages to the specified server in EMBLEM format.
The following steps show you how to configure a Security Appliance to send syslog messages:
Step 1 Designate a host to receive the messages with the logging host
command:
Pixfirewall(config)#logging host inside 10.1.1.10
NOTE This option is available only for UDP syslog messages, used by the RME syslog
analyzer.
260 Chapter 10: Syslog and the Cisco Security Appliance
You can specify additional servers so that if one goes offline, another is
available to receive messages.
Step 2 Set the logging level with the logging trap command:
Pixfirewall(config)#logging trap informational
If needed, set the logging facility command to a value other than its
default of 20. Most UNIX systems expect the messages to arrive at
facility 20.
Step 3 Start sending messages with the logging on command. To disable
sending messages, use the no logging command.
Step 4 To view your logging setting, enter show logging.
Centrally managing several Cisco Security Appliances can be challenging if you cannot
identify the origin of a particular message that is sent to the central log server. The Security
Appliance supports defining a unique device ID for log messages sent to a syslog server. If
several Security Appliances are configured to send their syslog messages to a single syslog
server, a unique identification can be configured so the message source can be identified. To
enable this option, use the following command:
logging device-id {hostname | ipaddress if_name | string text}
Table 10-4 gives a description of the parameters of the logging device-id command.
NOTE In the event that all syslog servers are offline, the Cisco Security Appliance stores
up to 100 messages in its memory. Subsequent messages that arrive overwrite the buffer
starting from the first line. PIX buffer logging is enabled by the command logging buffered
level.
Table 10-4 logging device-id Command Parameters
Parameter Description
hostname The name of the Security Appliance
ipaddress Specifies to use the IP address of the specified Security Appliance interface to
uniquely identify the syslog messages from the PIX Firewall
if-name The name of the interface with the IP address that is used to uniquely identify
the syslog messages from the Security Appliance
string text Specifies the text string to uniquely identify the syslog messages from the
Security Appliance
Configuring the ASDM to View Logging 261
When this feature is enabled, the message will include the specified device ID (either the
hostname or IP address of the specified interface—even if the message comes from another
interface—or a string) in messages sent to a syslog server. The Cisco Security Appliance will
insert the specified device ID into all non-EMBLEM-format syslog messages.
To disable this feature, use the following command:
no logging device-id
Configuring SNMP