Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

Can I monitor if a rule is triggered on a Cisco ASA?

Hi,

Not sure how I can do this, but I have a windows server on a VLAN (DMZ). I have a Cisco ASA and off the ASA a Cisco 3750 which I have all my VLAN's for my DMZ's. I have been asked to monitor if a port on a server gets triggered, is this possible?

Basically we want to know if any Internet users are accessing the server on this port.

I just don't know where to start on this.

Thanks

3 REPLIES
Gold

Re: Can I monitor if a rule is triggered on a Cisco ASA?

I assume you mean TCP port.

You can do this with either an IDS solution or with a SIM solution, like MARS. If you already have one, you could also probably do this with most syslog aggregator products. The key with using the SIM or syslog aggregator solution is getting the log from the ASA to the SIM/aggregator and then creating a "rule" to generate the alert.

New Member

Re: Can I monitor if a rule is triggered on a Cisco ASA?

All I have is a syslog server, are the other tools you mention free?

Gold

Re: Can I monitor if a rule is triggered on a Cisco ASA?

No, but your syslog server might be able to do it. Can it generate an email based on the content of the syslog?

258
Views
0
Helpful
3
Replies