cc/td/doc/product/iaabu/pix/pix_v51
hometocprevnextglossaryfeedbacksearchhelp
PDF

Table of Contents

Installing the PIX Firewall Syslog Server (PFSS)

Installing the PIX Firewall Syslog Server (PFSS)

The PIX Firewall Syslog Server (PFSS) lets you view PIX Firewall event information from a Windows NT system and includes special features not found on other syslog servers such as the following:

PFSS can receive syslog messages from up to 10 PIX Firewall units. You can install this product for use with any PIX Firewall model.

This chapter includes the following sections:

Important PFSS Notes

Review the following notes before installing PFSS:

    1. You must have access to Cisco Connection Online (CCO) to obtain a copy of the PFSS file.

    2. In version 5.1, PFSS now uses the modification date when renaming files. For example, it has been a week today since you started PFSS. Today, PFSS will see that there is already a monday.log file so it looks at the modification date of the monday.log file and sees that, for example, it was last modified on Jan 24, 2000. PFSS renames the monday.log file to monday.012400 and puts it in the backup directory, then creates the new monday.log file for today.

A backup directory is created within the log file directory where the day.mmddyy files go after being renamed.

    3. You should install Service Pack 6 on the Windows NT system to ensure that the Windows NT system is Y2K compliant.

    4. If a PIX Firewall is set to send messages via TCP and if the Windows NT partition containing the log files becomes full, PFSS causes the PIX Firewall to stop all connections until the Windows NT disk space is freed.

    5. When you install PFSS on the Windows NT system, write down the values you supply. Once PFSS is installed, the only way you can view the timer durations is by examining the Windows NT registry with regedit and searching for disk_empty_watch. Also, if you need to view the information in the registry, do not change it in the registry. The information can only be changed by clicking Start>Settings>Control Panel>Services.

Once PFSS is installed and running, you can view the pfss.log file to see the settings for the percentage of disk full, and the TCP and UDP ports. The pfss.log file can be found in the same directory in which you locate the log files. (During installation you are prompted for the directory in which to install the log files.)

    6. Only install PFSS on a Windows NT system version 4.0 system with Service Pack 3 installed. Install PFSS in the NTFS (not the FAT32) partition on your hard disk.

    7. You can install PFSS from either a user or the Administrator login.

    8. PFSS log files must reside on the local Windows NT system (not accessed across the network).

    9. The PIX Firewall Manager (PFM) and PFSS cannot be used together even if installed on different systems. The PFSS or PFM installation script detects the presence of the other program on the same system and advises you to deinstall the other program.

    10. PFSS creates seven rotating syslog files named monday.log, tuesday.log, wednesday.log, thursday.log, friday.log, saturday.log, and sunday.log. If a week has passed since the last log file was created, it will rename the old log file to day.mmddyy where day is the current day, mm is the month, dd is the day, and yy is the year. The size of a log file depends on how many connections can occur on each PIX Firewall and the types of messages you permit to be logged. Refer to the System Log Messages for the Cisco Secure PIX Firewall Version 5.1.

Installing PFSS

Follow these steps to install the PFSS:


Step 1 Obtain the PFSS installation program from Cisco Connection Online (CCO):

Step 2 If you have not done so already, open the window of the folder containing the downloaded file. Start the installation by double-clicking the downloaded file.

Step 3 You will be prompted for the following:


Refer to the logging command page in the configuration guide for your respective software version referenced in the section, "Related Documentation" in "About This Manual." This command page provides additional important information about configuring the PIX Firewall for use with PFSS.

The PFSS starts immediately after installation. This service can be controlled via the Services Control Panel, which you can use to pause the service, then resume the service, stop, or start the service. The service can also be started with different startup parameters from the Services window.

Changing PFSS Options

After you complete the installation, follow these steps to change the option values:


Step 1 On the Start>Settings>Control Panel>Services menu, click the PIX Firewall Syslog Server entry. You can add commands to the Startup Parameters edit box. After you enter a command, click Start. If you press the Enter key, the menu closes without information being accepted.

Step 2 Change the values by entering one of these commands:

Step 3 Refer to the logging command page in the configuration guide for a description for how to configure the PIX Firewall to work with the PFSS. You can view this document online for your respective software version referenced in the section, "Related Documentation" in "About This Manual."



hometocprevnextglossaryfeedbacksearchhelp
Posted: Fri Jun 2 09:54:21 PDT 2000
Copyright 1989 - 2000©Cisco Systems Inc.