# Configuring Cisco Devices - FirePOWER - [Configure Logging on FTD via FMC](https://www.manageengine.com/products/firewall/help/configure-cisco-firepower-firewalls.html#ftd_via_fmc) - [Configuring Cisco ASA with FirePOWER services](https://www.manageengine.com/products/firewall/help/configure-cisco-firepower-firewalls.html#asa_with_firepower) ## Configure Logging on FTD via FMC ### [1] Accessing Platform Settings All logging related configurations can be accessed by navigating to the **Devices > Platform Settings** tab. ![Cisco Firepower configuration in Firewall Analyzer: Platform settings](https://www.manageengine.com/products/firewall/help/images/cisco-firepower-1.png) To edit an existing policy, click the pencil icon. To create a new policy, click **New Policy** and select **Threat Defense Settings**. ![Cisco Firepower configuration in Firewall Analyzer: New policy](https://www.manageengine.com/products/firewall/help/images/cisco-firepower-2.png) Select the appropriate FTD appliance and click **Save**. ![Cisco Firepower configuration in Firewall Analyzer: Syslog settings](https://www.manageengine.com/products/firewall/help/images/cisco-firepower-3.png) ### [2] Logging Setup To configure logging (Local and External): - Go to **Devices > Platform Settings > Syslog > Logging Setup**. - **Enable Logging:** Must be checked. - Not required to select: - **Enable Logging on the failover standby unit** - **Send syslogs in EMBLEM format** - **Send debug messages as syslogs** - Click **Save**, then **Deploy** - Choose the FTD appliance where you want to apply the changes, and click **Deploy** in order to start deployment of the platform setting. ### [3] Event Lists 1. Navigate to **Device > Platform Settings > Threat Defense Policy > Syslog > Event List**. 2. Click on **Add** and add the below syslog event ID(s) under Event List: 430001, 430002, 430003, 430004, 430005 ![Cisco Firepower configuration in Firewall Analyzer: Syslog settings](https://www.manageengine.com/sites/meweb/images/firewall/images/fmc_ftd_430001_to_430005.png) **Save** the changes and deploy the changes. **Note:** These syslog message ID(s) will provide the "Rule" information. It will help to populate the Used Rules report and Unused Rules report. For more details, refer this [link](https://www.cisco.com/c/en/us/td/docs/security/firepower/Syslogs/fptd_syslog_guide/security-event-syslog-messages.html#id_87692) ### [4] Rate Limiting Syslog Navigate to **Device > Platform Settings > Threat Defense Policy > Syslog > Rate Limit**. Options available: - Logging level - Syslog levels **Note:** Not required to add any entries in Logging level and Syslog levels. ### [5] Syslog Settings Navigate to **Device > Platform Settings > Threat Defense Policy > Syslog > Syslog Settings**. - **Facility:** A facility code is used to specify the type of program that is logging the message. Messages with different facilities can be handled differently. From the Facility drop-down list, choose the "Local7(23)" facility. - **Enable Timestamp on each Syslog Message:** Check the Enable Timestamp on each Syslog Message check box in order to include the time stamp in Syslog messages. - **Enable Syslog Device ID:** Check the Enable Syslog Device ID check box in order to include a device ID in non-EMBLEM-format Syslog messages. ![Cisco Firepower configuration in Firewall Analyzer: Syslog settings](https://www.manageengine.com/products/firewall/help/images/cisco-firepower-4.png) Configure custom events list as needed. Click **Save**, then **Deploy** the configuration to the selected FTD appliance. #### Syslog IDs to Configure: - Traffic Syslog IDs: 106015, 106023, 106100, 302013, 302014, 302015, 302016 - [Security Events](https://www.manageengine.com/products/firewall/help/configure-cisco-firewalls.html#security_breach_log_ids) - [VPN Events](https://www.manageengine.com/products/firewall/help/configure-cisco-firewalls.html#vpn_log_ids) ### Configure External Logging Navigate to **Device > Platform Settings > Threat Defense Policy > Syslog > Logging Destinations**. FTD supports these types of external logging: - FTD supports these types of external logging. - SNMP trap: Sends the logs out as an SNMP trap. - E-Mail: Sends the logs via email with a preconfigured mail relay server. The configuration for the external logging and the internal logging are the same. The selection of Logging destinations decides the type of logging that is implemented. It is possible to configure Event Classes based on Custom Event lists to the remote server. #### Remote Syslog Server Setup Syslog servers can be configured to analyze and store logs remotely from the FTD. There are three steps to configure remote Syslog servers. 1. Go to **Syslog Servers** under **Threat Defense Policy**. 2. Configure parameters: - **Allow user traffic to pass when TCP syslog server is down:** If a TCP Syslog server has been deployed in the network and it is not reachable, then the network traffic through the ASA is denied. This is applicable only when the transport protocol between the ASA and the Syslog server is TCP. Check the Allow user traffic to pass when TCP syslog server is down check box in order to allow traffic to pass through the interface when the Syslog server is down. - **Message Queue Size:** The message queue size is the number of messages that queues up in the FTD when the remote Syslog server is busy and does not accept any log messages. The default is 512 messages and the minimum is 1 message. If 0 is specified in this option, the queue size is considered to be unlimited. ![Cisco Firepower configuration in Firewall Analyzer: Remote syslog server setup](https://www.manageengine.com/products/firewall/help/images/cisco-firepower-5.png) 3. Click **Add** to configure the server: - **IP Address:** From the IP Address drop-down list, choose a network object which has the Syslog servers listed. If you have not created a network object, click the plus (+) icon in order to create a new object. - **Protocol:** Click either the TCP or UDP radio button for Syslog communication. - **Port:** 1514 - **Available Zones:** Enter the security zones over which the Syslog server is reachable and move it to the Selected Zones/Interfaces column. ![Cisco Firepower configuration in Firewall Analyzer: Add syslog server](https://www.manageengine.com/products/firewall/help/images/cisco-firepower-6.png) Click **Save** in order to save the platform setting. Choose **Deploy**, choose the FTD appliance where you want to apply the changes, and click **Deploy** in order to start deployment of the platform setting. **Reference:** [Cisco Official Guide](https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/200479-Configure-Logging-on-FTD-via-FMC.html) ## Configuring Cisco ASA with FirePOWER Services ### Creating a Syslog Alert Response 1. Go to **ASA Firepower Configuration > Policies > Actions > Alerts**. 2. From the **Create Alert** menu, choose **Create Syslog Alert**. 3. Enter the following details: - **Name:** Name of the alert - **Host:** IP/hostname of the Firewall Analyzer server - **Port:** 1514 - **Facility:** LOCAL7 - **Severity:** INFO 4. Click **Save** ![Cisco Firepower configuration in Firewall Analyzer: Syslog alert response creation](https://www.manageengine.com/products/firewall/help/images/cisco-firepower-7.jpg) ### Configuring Logging for Traffic Events 1. Navigate to **ASA Firepower Configuration > Policies > Access Control Policy** 2. Edit the desired rule and go to the **Logging** options. 3. Select: - Log at Beginning of Connection - Log at End of Connection - Send Connection Events to: **Syslog**, then select the Syslog Alert Response 4. Click **Save** ![Cisco Firepower configuration in Firewall Analyzer: Traffic events](https://www.manageengine.com/products/firewall/help/images/cisco-firepower-8.jpg) For more details, refer to: - [Configure-Logging-in-Firepower-Module-fo.pdf](https://www.manageengine.com/products/firewall/help/configure-cisco-firepower-firewalls.html#ftd_via_fmc) - [Configuring_External_Alerting.pdf](https://www.manageengine.com/products/firewall/help/configure-cisco-firepower-firewalls.html#asa_with_firepower)