VPN 3005, syslog and Kiwi service

VPN 3005, syslog and Kiwi service

NewsGroups | Search | Tools
 comp.dcom.sys.cisco  Post an article  get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content  add this group's latest topics to your Google content  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
VPN 3005, syslog and Kiwi service thufur 05-18-2006
Posted by thufur on May 18, 2006, 10:32 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Running 3005 concentrator, doing radius on win 2000 server, running
kiwi on same server

My question is, I would like to get syslog messages sent only when
users connnect and disconnect. I dont have access to ACS software
On the 3005, under
Configuration-> Events-> General
I have Log, Console, and Syslog set to Use Event List, and I would like
some advice on changes I can make in the Event List
I would only like IKE/ 50,SEV(5) and IKE/ 66,SEV(5) messages to be
sent, but I am also getting
IKE/ 172, IKE/ 184, IKE/ 25, IKE/ 34, IKE/ 75 and IKE/ 194 messages
sent over, and only if I set up SNMP trapping. I have the server set
up under syslog server, port 514, Auth Facility tag.

Any ideas about something I might be doing that is blindingly wrong?
Thanks for any help.


Posted by Martin Bilgrav on May 24, 2006, 5:12 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
you need to configured the Class individually.
I suggeust you use AUTH-6 level inorder to get the info you need.
If you like you can turn of the others.

HTH
Martin Bilgrav

> Running 3005 concentrator, doing radius on win 2000 server, running
> kiwi on same server
>
> My question is, I would like to get syslog messages sent only when
> users connnect and disconnect. I dont have access to ACS software
> On the 3005, under
> Configuration-> Events-> General
> I have Log, Console, and Syslog set to Use Event List, and I would like
> some advice on changes I can make in the Event List
> I would only like IKE/ 50,SEV(5) and IKE/ 66,SEV(5) messages to be
> sent, but I am also getting
> IKE/ 172, IKE/ 184, IKE/ 25, IKE/ 34, IKE/ 75 and IKE/ 194 messages
> sent over, and only if I set up SNMP trapping. I have the server set
> up under syslog server, port 514, Auth Facility tag.
>
> Any ideas about something I might be doing that is blindingly wrong?
> Thanks for any help.
>



Similar ThreadsPosted
Kiwi Syslog October 6, 2005, 3:07 am
anyone using kiwi syslog? October 18, 2005, 11:03 am
How to public a service behind a PIX changing the port of the service. March 7, 2005, 12:48 pm
Kiwi Cat Tools July 24, 2008, 5:34 pm
Kiwi syslogging of Cisco 2811 through outside interface of Pix 501 January 28, 2007, 1:08 pm
Can a 3005 behind a PIX do a L2L VPN? March 30, 2005, 5:09 pm
WebVPN on a 3005 December 28, 2004, 11:51 am
VPN 2811 to 3005 June 16, 2005, 2:58 am
concentrator 3005 February 14, 2007, 9:16 am
VPN 3005 and dyndns? November 19, 2007, 2:51 pm

other useful resources:
The Federal Communications Commission (FCC)
Telecommunications Industry Association
Electronic and Software Security Products and Services
International Telecommunication Union

Custom CGI Perl and PHP programming by 1-Script.com

Contact Us | Privacy Policy
The site map in XML format XML site map