FirewallWizards
[Top] [All Lists]

Re: [fw-wiz] [OT?] Accounting from PIX Logs

To: Firewall Wizards Security Mailing List <firewall-wizards@listserv.icsalabs.com>
Subject: Re: [fw-wiz] [OT?] Accounting from PIX Logs
From: Shahin Ansari <zohal52@yahoo.com>
Date: Wed, 28 Mar 2007 09:32:26 -0700 (PDT)
Delivered-to: sp-com-lists@consult.net
Delivered-to: fwwizards-list2@consult.net
Delivered-to: firewall-wizards@listserv.cybertrust.com
In-reply-to: <92db0b590703280542s4b275793k1e35cfcc1adcca4d@mail.gmail.com>
List-archive: <https://listserv.icsalabs.com/pipermail/firewall-wizards>
List-help: <mailto:firewall-wizards-request@listserv.icsalabs.com?subject=help>
List-id: Firewall Wizards Security Mailing List <firewall-wizards.listserv.icsalabs.com>
List-post: <mailto:firewall-wizards@listserv.icsalabs.com>
List-subscribe: <https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards>, <mailto:firewall-wizards-request@listserv.icsalabs.com?subject=subscribe>
List-unsubscribe: <https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards>, <mailto:firewall-wizards-request@listserv.icsalabs.com?subject=unsubscribe>
Reply-to: Firewall Wizards Security Mailing List <firewall-wizards@listserv.icsalabs.com>
Sender: firewall-wizards-bounces@listserv.icsalabs.com
Is there any tools or scripts that would help with huge access list update etc?

Security Guy <security@sligoinc.com> wrote:
This perl script might help you:

http://groups.google.ca/group/comp.dcom.sys.cisco/browse_thread/thread/972a527ba458f06/37ddb0b6234c1e48#37ddb0b6234c1e48

another option (also discussed in that thread) would be to mirror the
inside port of the PIX and run traffic analysis against that (there
are numerous apps that will do this for you, I just can't think of any
off the top of my head), but this would require a switch that supports
mirroring and another box to do the analysis. More complicated, but
you're probably going to get a more accurate reading than groking what
you get from the PIX syslog output

HTH

-Karl

On 3/27/07, Adrian Grigorof wrote:
>
> Hello,
>
> Not open source but good (we hope):
> http://www.eventid.net/firegen/firegenpix2.asp (I am one of
> the developers).
>
> Regards,
>
> Adrian Grigorof
> www.altairtech.ca
> www.eventid.net
>
>
>
> fRANz wrote:
> Hi.
> Anyone can suggest me a good solution (preferred OpenSource) for
> summarizing and accounting Cisco PIX (ver. 6.x, 7.x) logs?
>
> Regards,
> -f
> _______________________________________________
> firewall-wizards mailing list
> firewall-wizards@listserv.icsalabs.com
> https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
>
>
>
>
>
> _______________________________________________
> firewall-wizards mailing list
> firewall-wizards@listserv.icsalabs.com
> https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
>
>


--
-Karl
_______________________________________________
firewall-wizards mailing list
firewall-wizards@listserv.icsalabs.com
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards


Be a PS3 game guru.
Get your game face on with the latest PS3 news and previews at Yahoo! Games.
_______________________________________________
firewall-wizards mailing list
firewall-wizards@listserv.icsalabs.com
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
<Prev in Thread] Current Thread [Next in Thread>