Configuring Cyberoam


 

Firewall Analyzer supports Cyberoam Firewall Version: 9.5.4 build 66 onwards

Configuring Cyberoam

On the Cyberoam Firewall Web Admin Console do the following.

  1. Select System > Logging > Manage Syslog
  2. Specify unique name for Syslog server
  3. Specify IP address and port of the syslog server. Cyberoam will send logs to the configured IP address. The default port is 514
  4. Select Facility. Facility indicates the source of a log message to the syslog server. You can configure Facility to distinguish log messages from different Cyberoam Firewalls
  5. Select the Severity level of the messages logged. Severity level is the severity of the message that has been generated

 

Note

Cyberoam logs all messages at and above the logging severity level you select. For example, select ‘ERROR’ to log all messages tagged as ‘ERROR,’ as well as any messages tagged with ‘CRITICAL,’ ‘ALERT’ and ‘EMERGENCY’ and select ‘DEBUG’ to log all messages.

Note: Firewall Analyzer requires the severity level as 'INFORMATIONAL'.

 

  1. Click Create to save the configuration.

 

Also you need to enable logging on each rule to monitor allowed and denied traffic. Please follow the below steps.

 

 

Configure Cyberoam Firewall


Copyright © 2012, ZOHO Corp. All Rights Reserved.
ManageEngine