Security Compliance
Enable SEM to Track Cisco Firewall NAT Buildup and Teardown Events
How to track buildup and teardown events in SEM for Cisco Firewall NAT.
First published date
Last published date
Overview
Tracking buildup events
Security Event Manager (formerly Log & Event Manager) can be configured to capture Cisco firewall buildup events, too. The primary buildup event to use for TCP tracking is 302013. Other buildup events include 302015, 302017, 302020, 302303, 305009, 305011, and 609011. Check the descriptions of these events in the Cisco System Log Messages Guide (© 2018 Cisco, available at https://www.cisco.com/, obtained on December 5, 2018) to make sure those are events you want to capture.Out of the box, SEM captures events 302003, 302009, and 603108.
Tracking teardown events
You can also enable SEM to capture teardown NAT events. The teardown sibling to buildup even 302013 is 302014. Other events include 302016, 302018, 302021, 302304, 305010, 305012, 617100, and 609002. You can also descriptions of these events in the Cisco System Log Messages Guide (© 2018 Cisco, available at https://www.cisco.com/, obtained on December 5, 2018) to make sure they are ones you want to capture.Out of the box, SEM captures event 603019.
Product section
Resolution
To enable the latest SEM connector to capture buildup/teardown NAT events:
- Ensure your firewalls are configured to log to SEM and that the appropriate SEM connector is configured to monitor for your firewall data. You may also need the CiscoFirewalls_buildup_teardown custom connector, which you can get by logging a support ticket with Solarwinds.
- Access the firewalls you will monitor buildup/teardown messages from and adjust the severity level of those events from 6 (the default) to 0. For more information about changing the severity level of an ASA message, check the Cisco ASA Guides (© 2018 Cisco, available at https://www.cisco.com/, obtained on December 5, 2018).
Considerations
A few things to consider include:
- To monitor "accepted traffic," use the log target in your accept ACLs instead of the buildup logging. This lets you control what accepted traffic you are made aware of.
- To monitor the information about the actual NAT, consider the event load this will create. Plan a test phase where you turn it on, determine if it is valuable to you for investigating (try some test scenarios), and then turn it off if you determine its value.
- Consider the nDepth original log message store, if you are interested in unmodified log data (versus the normalized data). Note that this consumes disk space.
- Consider whether you need both buildups and teardowns. The teardown NAT messages include the same information as the built messages, along with some duration and size information that may or may not be useful. A lot of colleges and universities that are using the built messages do not rely on the teardown messages, they only need to know a connection was established for verification/analysis/correlation.
- Check the syslog data to determine which buildup and/or teardown events are of use.
Disclaimer: Please note, any content posted herein is provided as a suggestion or recommendation to you for your internal use. This is not part of the SolarWinds software or documentation that you purchased from SolarWinds, and the information set forth herein may come from third parties. Your organization should internally review and assess to what extent, if any, such custom scripts or recommendations will be incorporated into your environment. You elect to use third party content at your own risk, and you will be solely responsible for the incorporation of the same, if any.