- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- Syslog Over TCP
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Syslog Over TCP
Hi Team,
I know by default syslog uses UDP 514, is there a way to enforce TCP use when sending logs from the checkpoint side?
I am thinking since syslog uses both TCP and UDP and the port number is the same, if the syslog server is configure to accept only TCP, checkpoint should be able to work with that.
If there is a way to force checkpoint to send the logs over TCP, please let me know.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Create NAT rule?
Original Source: firewall
Original Destination: Syslog server
Original Service: udp_514
Translated Source: original
Translated Destination: original
Translated Service: tcp_514
Jozko Mrkvicka
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Well, implied rules come first before any other rules so that mean--I have to disable the implied and create explicit rule.
Checkpoint should be able to decide what services it should use base on the server setting--if the server is configure to use tcp 514--send logs using that but I dont think it do--which is sad to say.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Sorry, but NAT does not work this way. It can change port numbers, but not protocols.
