I have configurated my pix 515 (ver. 6.22) to logging to my webtrend server
everything seems ok ,the logging level is debugging
but something wrong
all my hosts on inside can not use DNS to reslove DNS (port 53 )name to access the internet , my network is ok !!! (I have check all my routers, L3 switch , pix .etc ,and I try to ping and use the the real ip address to access to some web site on internet, like http://real ip address , the connection is ok!!,
then I try my own DNS inside and the other Isp DNS , but can not work
If you're logging via TCP, try logging via UDP and see if it changes anything.
With TCP logging, the pix does not allow traffic until it can log it. So it might be waiting for confirmation from the syslog server, and maybe this causes DNS timeouts, especially if you have a high load.
With UDP logging, the pix allows the traffic and sends the syslog message (without waiting for confirmation).
Anyway, it is recommended to configure all internal hosts to use internal DNS servers, and only the internal DNS servers to forward to ISP servers when needed.
DocumentationCode download linksGoalRequirementLimitationsSupported ISR and UCS-E ModelSupported ISRG2 and UCS-E Blades:Supported ISR4K and UCS-E Blades:Step by Step ConfigurationConfigure one of the connectivity options to access the Cisco IMC from the n...
Firepower Threat Defense (NGFWv) on UCS E-series - Transparent Mode in HA
DocumentationCode download linksGoalRequirementLimitationsSupported ISR and UCS-E ModelSupported ISRG2 and UCS-E Blades:Supported ISR4K and UCS-E Blades:Step by Step ConfigurationCo...
I am currently unable to specify "crypto keyring" command when configuring VPN connection on my cisco 2901 router.
The following licenses have been activated on my router :