<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Activate logging in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/activate-logging/m-p/170321#M54028</link>
    <description>&lt;P&gt;Hi,&lt;BR /&gt;I can't view in my Kiwi Syslog the traffic from my outside interface.&lt;BR /&gt;In my PA-500 I've enabled SNMP in Device -&amp;gt; Management -&amp;gt;Management Interface Settings -&amp;gt; Permitted SNMP Service.&lt;BR /&gt;In Operations -&amp;gt; SNMP Setup -&amp;gt; activeted Use Event-Specific Trap Definitions with Version V2c and SNMP community string.&lt;BR /&gt;Under Device -&amp;gt; Server Profiles -&amp;gt; Syslog, I activated Name, IP Syslog Server, Trasport UDP, Port 514, Format BSD and Facility LOG_USER.&lt;BR /&gt;In Device -&amp;gt; Server Profiles -&amp;gt; SNMP Trap, I activated SNMP Manager IP and Community with Version V2c.&lt;BR /&gt;In Policies -&amp;gt; Security, I actived the log forwarding profile in many rules.&lt;/P&gt;&lt;P&gt;Is there someone that can help me?&lt;/P&gt;</description>
    <pubDate>Mon, 07 Aug 2017 14:17:40 GMT</pubDate>
    <dc:creator>s_quasar</dc:creator>
    <dc:date>2017-08-07T14:17:40Z</dc:date>
    <item>
      <title>Activate logging</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/activate-logging/m-p/170321#M54028</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;I can't view in my Kiwi Syslog the traffic from my outside interface.&lt;BR /&gt;In my PA-500 I've enabled SNMP in Device -&amp;gt; Management -&amp;gt;Management Interface Settings -&amp;gt; Permitted SNMP Service.&lt;BR /&gt;In Operations -&amp;gt; SNMP Setup -&amp;gt; activeted Use Event-Specific Trap Definitions with Version V2c and SNMP community string.&lt;BR /&gt;Under Device -&amp;gt; Server Profiles -&amp;gt; Syslog, I activated Name, IP Syslog Server, Trasport UDP, Port 514, Format BSD and Facility LOG_USER.&lt;BR /&gt;In Device -&amp;gt; Server Profiles -&amp;gt; SNMP Trap, I activated SNMP Manager IP and Community with Version V2c.&lt;BR /&gt;In Policies -&amp;gt; Security, I actived the log forwarding profile in many rules.&lt;/P&gt;&lt;P&gt;Is there someone that can help me?&lt;/P&gt;</description>
      <pubDate>Mon, 07 Aug 2017 14:17:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/activate-logging/m-p/170321#M54028</guid>
      <dc:creator>s_quasar</dc:creator>
      <dc:date>2017-08-07T14:17:40Z</dc:date>
    </item>
    <item>
      <title>Re: Activate logging</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/activate-logging/m-p/170338#M54029</link>
      <description>&lt;P&gt;I would perform a PCAP or a wireshark on your Kiwi server and see if you can tell exactly what's happening. WIthout actually seeing your configuration or knowing how your Kiwi server is setup it's pretty hard to see if something this misconfigured.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Aug 2017 16:06:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/activate-logging/m-p/170338#M54029</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-08-07T16:06:20Z</dc:date>
    </item>
    <item>
      <title>Re: Activate logging</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/activate-logging/m-p/174133#M54746</link>
      <description>&lt;P&gt;I've installed a MIBs software to walk into it.&lt;/P&gt;&lt;P&gt;I contacted the IP that I found in Device -&amp;gt; Management -&amp;gt; Managemente interface settings. The SNMP service and community string are activated.&lt;/P&gt;&lt;P&gt;When I try to contact the IP fro MIBs informations, in monitor I find from my zone SERVER that I've contacted OUTSIDE zone for the IP 192.168.1.1 that is different from my console IP management that is 10.254.1.1. But why outside zone? Here there are only public IPs. I'm confusing.&lt;/P&gt;</description>
      <pubDate>Thu, 31 Aug 2017 14:07:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/activate-logging/m-p/174133#M54746</guid>
      <dc:creator>s_quasar</dc:creator>
      <dc:date>2017-08-31T14:07:43Z</dc:date>
    </item>
    <item>
      <title>Re: Activate logging</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/activate-logging/m-p/177893#M55425</link>
      <description>&lt;P&gt;Is there someone that can help me?&lt;/P&gt;</description>
      <pubDate>Wed, 20 Sep 2017 15:50:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/activate-logging/m-p/177893#M55425</guid>
      <dc:creator>s_quasar</dc:creator>
      <dc:date>2017-09-20T15:50:03Z</dc:date>
    </item>
    <item>
      <title>Re: Activate logging</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/activate-logging/m-p/177894#M55426</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/51438"&gt;@s_quasar&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Can you include a screenshot of what you are seeing from your end.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Sep 2017 15:58:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/activate-logging/m-p/177894#M55426</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-09-20T15:58:09Z</dc:date>
    </item>
    <item>
      <title>Re: Activate logging</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/activate-logging/m-p/178204#M55489</link>
      <description>&lt;P&gt;I'm not sure, but I think you are saying that the snmp configuration is being sourced from the outside interface instead of the dedicated management port.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Check to see if your PA has a service route configured that overrides the default sourcing of this managment traffic and puts it on the configured port needed for the the route. &amp;nbsp;This setting is located here.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Device &amp;gt; Setup &amp;gt; Services&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Service route&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Sep 2017 21:03:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/activate-logging/m-p/178204#M55489</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2017-09-21T21:03:46Z</dc:date>
    </item>
    <item>
      <title>Re: Activate logging</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/activate-logging/m-p/182330#M56169</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I've controlled and I have the service SNMP trap&amp;nbsp;in default mode. This is the only service with SNMP name inside.&lt;/P&gt;&lt;P&gt;The strange thing is the IP 192.168.1.1 in management&amp;nbsp; that is a private IP. In the gateaway I have a public IP. This is a configuration from the company that has installed the firewall. Can I reach that private IP?&amp;nbsp;Do I need to have a specific configuration in the firewall rules?&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2017 12:33:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/activate-logging/m-p/182330#M56169</guid>
      <dc:creator>s_quasar</dc:creator>
      <dc:date>2017-10-17T12:33:51Z</dc:date>
    </item>
    <item>
      <title>Re: Activate logging</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/activate-logging/m-p/183212#M56333</link>
      <description>&lt;P&gt;I'm having trouble following exactly what the configuration is.&amp;nbsp; Note that the snmp traps with your outline in the first post will be sourced from the mgmt interface address towards the configured syslog kiwi server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Check that the route and path from mgmt interface to kiwi is up and working.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Check that security policies along this path permit the traps from the mgmt interface address source to the destination address of the kiwi server.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Oct 2017 12:36:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/activate-logging/m-p/183212#M56333</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2017-10-23T12:36:05Z</dc:date>
    </item>
  </channel>
</rss>

