Cisco FTD (syslog)

Configure Cisco FTD for syslog forwarding to Radiant Security.

Overview

Cisco FTD is a next-generation firewall and intrusion prevention system (IPS) solution. Cisco FTD offers a more complete security solution than Cisco ASA, which focuses on firewall functionality. This guide will walk you through the steps needed to configure Cisco FTD to forward logs to Radiant Security via syslog TLS.

In this guide, you’ll complete the following steps:

Prerequisites

  • The user must have the config role in Cisco
  • User must be able to deploy an Rsyslog configuration within their organization’s infrastructure, and set up networking so that this service can receive and send packets

Add the data connector in Radiant Security

1.   Log in to Radiant Security.

 
2.   From the navigation menu, click Settings > Data Connectors and click + Add Connector.
3.   Search for and select the Cisco FTD (syslog) vendor from the list and click Data Feeds. Screenshot 2024-04-04 at 13.33.17

 

4.   Under Select your data feeds, select Cisco FTD and click Credentials. Screenshot 2024-04-04 at 13.34.13

 

5.   Under Credential Name, give the credential an identifiable name (e.g. Cisco FTD Credentials).  
6.   Under Required Credentials, add a Connector tag value. This value can be random and will be used as a salt to generate the unique connector Token which you’ll download in the next step. Screenshot 2024-04-04 at 13.36.58

 

7.   Click Add Connector.  
8.   Copy and save the Token value. Screenshot 2024-04-04 at 13.38.28

 

9.   Click Done to save your changes.  

Configure a local Radiant Security Syslog Collector

Refer to the Deploy a Radiant Security Syslog Collector guide to set up a local Radiant Syslog Collector.

Configure Cisco FTD to forward logs to the Radiant Security Log Collector

  1. Log into the Cisco FDM UI with a config user.

  2. Select the desired Cisco FTD device on the top navigation bar.

  3. Under System Settings, select Logging Settings.

  4. Enable Data Logging.

  5. Under Message Filtering for Firepower Threat Defense, set the Severity level for filtering all events as Information.Untitled

  6. Under Syslog Servers, click the + button to add a new syslog server.
  7. Click Create new Syslog Server.
  8. Enter the IP address of the Syslog Forwarder deployed to your environment previously.
  9. For Protocol Type select UDP.
  10. For Port Number enter 6514.
  11. Under Interface for Device Logs, select an interface with connectivity to the Syslog Forwarder.
  12. Click OK and select the newly created Syslog Server.
  13. Click SAVE to save the changes.Untitled(2)
  14. Click the deploy button to deploy the changes.Untitled(3)

We value your opinion. Did you find this article helpful? Share your thoughts by clicking here or reach to our Product and Customer Success teams at support@radiantsecurity.ai 

 

Last updated: 2024-08-23