Great Circle Associates Firewalls
(June 1994)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: RE: Cisco software update? (fwd)
From: ted . doty @ nsco . network . com
Date: Tue, 21 Jun 94 12:48:40 PDT
To: Andrew Molitor <amolitor @ anubis . network . com>, bede @ scotty . mitre . org
Cc: firewalls @ greatcircle . com

>   Date: Wed, 1 Jun 94 15:09:22 CDT
>   From: amolitor @
 anubis .
 network .
 com (Andrew Molitor)
>
>	   Well, since someone asked, I will take this chance to plug our stuff.
>   Network Systems routers allow you to wrap any packet you can match in a
>   filter (which allows you to select packets on really very precise criteria) 
up
>   in a UDP packet, and forward that somewhere.     [ . . . ]
>
>Could you give us more exact information about this?  It sounds a
>great deal like you're using UNIX syslog to log "interesting" router
>events, which would indicate that your real innovation here is in the
>runtime configuration (filter) controls on logging.
>
>- Bede McCall <bede @
 mitre .
 org>
>
>   The MITRE Corporation
>   Bedford, Massachusetts
>

Sorry for the delay, but has anyone explained this to you?  We do have a
syslog type of capability, but it has nothing to do with the audit (altho
you could probably cobble some type of logger out of it).

The audit actually sends a copy of the original datagram that caused the
event (as well as time/date, filter name, etc) to an audit daemon.

- Ted
--------------------------------------------------------------------------
Ted Doty, Network Systems Corporation | phone:      +1 301 596-2270
8965 Guilford Road, Suite 250         | fax:        +1 410 381-3320
Columbia, MD, 21046 USA               | voice mail: (800) 233-1485
--------------------------------------------------------------------------
Wenn ist das Nunstuck git und Slotermeyer? Ja! ... Beierhund das Oder
die Flipperwaldt gersput!


Indexed By Date Previous: Re: Security policy
From: "Mary L. Casey" <casey @ justice . usdoj . gov>
Next: What are the security risk in opening some UDP ports
From: loi @ gov . on . ca (Ian Lo)
Indexed By Thread Previous: Re: Cisco software update? (fwd)
From: ted . doty @ nsco . network . com
Next: Re: Router Preference (spin off from Cisco software update)
From: bmv @ mapp . org (BM.Vornbrock)

Google
 
Search Internet Search www.greatcircle.com