cc/td/doc/product/iaabu/pix/pix_v44
hometocprevnextglossaryfeedbacksearchhelp
PDF

Table of Contents

Installing the PIX Firewall Syslog Server

Installing the PIX Firewall Syslog Server

If you have PIX Firewall version 4.3 or later, the PIX Firewall Syslog Server (PFSS) lets you view PIX Firewall event information from a Windows NT system and includes special features not found on other syslog servers such as:

PFSS can receive syslog messages from up to 10 PIX Firewall units.

Important PFSS Notes

Review the following notes before installing PFSS:

    1. You must have access to Cisco Connection Online (CCO) to obtain a copy of the PFSS file.

    2. If a PIX Firewall is set to send messages via TCP and if the Windows NT partition containing the log files becomes full, PFSS causes the PIX Firewall to stop all connections until the Windows NT disk space is freed.

    3. When you install PFSS on the Windows NT system, write down the values you supply. Once PFSS is installed, the only way you can view the timer durations is by examining the Windows NT registry with regedit and searching for disk_empty_watch. Also, if you need to view the information in the registry, do not change it in the registry. The information can only be changed from the Start>Settings>Control Panel>Services item.

    Once PFSS is installed and running, you can view the pfss.log file to see the settings for the percentage of disk full, and the TCP and UDP ports. The pfss.log file can be found in the same directory in which you locate the log files. (During installation you are prompted for the directory in which to install the log files.)

    4. Only install PFSS on a Windows NT system version 4.0 system with Service Pack 3 installed. Install PFSS in the NTFS (not the FAT32) partition on your hard disk.

    5. You can install PFSS from either a user or the Administrator login.

    6. PFSS log files must reside on the local Windows NT system (not accessed across the network).

    7. The PIX Firewall Manager (PFM) and PFSS cannot be used together even if installed on different systems. The PFSS or PFM installation script detects the presence of the other program on the same system and advises you to deinstall the other program.

    8. PFSS creates seven rotating syslog files named monday.log, tuesday.log, wednesday.log, thursday.log, friday.log, saturday.log, and sunday.log. If a week has passed since the last log file was created, it will rename the old log file to day.mmddyy where day is the current day, mm is the month, dd is the day, and yy is the year. The size of a log file depends on how many connections can occur on each PIX Firewall and the types of messages you permit to be logged. Refer to the System Log Messages for the PIX Firewall for your respective software version listed in the section, "Related Documentation" in 'About This Manual.'

Installing PFSS

To install the PFSS:

Step 1 Obtain the PFSS installation program from Cisco Connection Online (CCO):

Step 2 If you have not done so already, open the window of the folder containing the downloaded file. Start the installation by double-clicking the downloaded file.

Step 3 You will be prompted for the following:

Refer to the logging command page in Chapter 5, "Command Reference" in the configuration guide for your respective software version listed in the section, "Related Documentation" in "About This Manual." This command page provides additional important information about configuring the PIX Firewall for use with PFSS.

The PFSS starts immediately after installation. This service can be controlled via the Services Control Panel, which you can use to pause the service, then resume the service, stop, or start the service. The service can also be started with different startup parameters from the Services window.

Changing PFSS Options

After you complete the installation, you can change the option values as follows:

Step 1 Select the PIX Firewall Syslog Server entry from the Start>Settings>Control Panel>Services menu. You can add commands to the Startup Parameters edit box. After you enter a command, click Start. If you press the Enter key, the menu closes without information being accepted.

Step 2 Change the values by entering one of these commands:

Step 3 Refer to the logging command page in the configuration guide in Chapter 5, "Command Reference" for a description for how to configure the PIX Firewall to work with the PFSS. You can view this document online for your respective software version in the section, "Related Documentation" in "About This Manual."


hometocprevnextglossaryfeedbacksearchhelp
Posted: Thu Jun 10 00:31:05 PDT 1999
Copyright 1989-1999©Cisco Systems Inc.