Pix Firewall logs to syslog - missing some logs (257 Views)
Reply
Occasional Contributor
AnishTS2005
Posts: 5
Registered: ‎07-05-2011
Message 1 of 4 (257 Views)
Accepted Solution

Pix Firewall logs to syslog - missing some logs

[ Edited ]

Hi All,

 

In our environment firewall logs are configured to update in syslog.

 

 

Firewall side configuration.

 

config

logging enable

logging timestamp

logging buffered errors

logging trap informational

logging history errors

logging host inside x.x.x.x

 

 

Syslog logging: enabled

    Facility: 20

 

syslog conf

 

local4.info     /logs/pix/xyz.log

 

*.info;local3.none;local4.none;local5.none;local6.none;local7.none;mail.none    /var/adm/syslog/syslog.log
*.alert;local3.none;local4.none;local5.none;local6.none;local7.none     /dev/console
*.alert;local3.none;local4.none;local5.none;local6.none;local7.none     root
*.emerg;local3.none;local4.none;local5.none;local6.none;local7.none     *

 

But now the issue is,

 

for a particluar time,  say one minute,

 

if we log it to server1, it logs around 200 messages in server1 /logs/pix/xyz.log.

but if we log it to server2 it logs around 2000 messages in server2 /logs/pix/xyz.log.

 

What can be the issue.

 

Warm Regards,

Anish

Please use plain text.
Honored Contributor
Matti_Kurkela
Posts: 6,271
Registered: ‎12-02-2001
Message 2 of 4 (237 Views)

Re: Pix Firewall logs to syslog - missing some logs

If the network between the firewall and server1 has a lot of other traffic, some of the log messages may be dropped in transit. The syslog protocol is very basic and does not have any protections against lost messages.

MK
Please use plain text.
Occasional Contributor
AnishTS2005
Posts: 5
Registered: ‎07-05-2011
Message 3 of 4 (226 Views)

Re: Pix Firewall logs to syslog - missing some logs

Hi MK,

Thank you. Let me check it out .

Warm Regards,
Anish T S
Please use plain text.
Occasional Contributor
AnishTS2005
Posts: 5
Registered: ‎07-05-2011
Message 4 of 4 (206 Views)

iRe: Pix Firewall logs to syslog - missing some logs

Hi MK & All,

 

Issue is resolved. It has taken long time to trouble shoot. Used tusc to identify the root cause. In resolv.conf entry 127.0.0.1 was there.

 

while addding data to syslog syslogd is doing dns lookups to localhost where no dns server was setup. So syslog is waiting for around 5 seconds to time out dns query. During this time lot of logs will  discarded.  Since its syslog protocol as you said it will not be regenerated. So we commented out the 127.0.0.1 in resolv.conf and now everything is fine.

 

Warm Regards,

Anish T S

 

Please use plain text.
The opinions expressed above are the personal opinions of the authors, not of HP. By using this site, you accept the Terms of Use and Rules of Participation