Features Inquiry

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Features Inquiry

L2 Linker

Hello Guys,

I would like to know if there is an alert feature in PAN where it will alert (via Email, Syslog,snmp or other Log forwarding) the administrators whenever someone is trying to login in the device.

also, is there a plan in adding a Configuration Forwarding to PAN? basically PAN will just send the latest config to a FTP server or other file transfer.

Thanks in advance.

-hartkently

1 accepted solution

Accepted Solutions

L7 Applicator

Few related information for alert notification to Email,syslog , snmp or other Log forwarding:

Email alerts,.

How to Configure Email Alerts for System Logs?

How to Setup Email Alerts

Example:

(A) The login information under SYSTEM logs will be "informational"

login-logs.JPG.jpg

(B) Create a server profile for SYSLOG and email notification.

syslog-1.JPG.jpg

(C)  Edit the "infomational" log settings under System>, add the configured SYSLOG server and email profile.

syslog-2.JPG.jpg

(D)  Set up a log forwarding profile under Object > Log forwarding

syslog-3.JPG.jpg

Hope this helps.

Thanks

View solution in original post

5 REPLIES 5

L7 Applicator

Hello,

The firewall does not have an option to back up the config until and unless you use xmli api. If you have a panorama managing your device you can schedule a config export by navigating to Panorama-Schedule Config export--use ftp/scp.

Related notes:

automatic config backup option

Re: Saving and Exporting Configs

schedule

As per my knowledge, the XML-API backup works fantastically.

How to use the XML API to backup your firewall configuration

Hope this helps.

Thanks

L7 Applicator

Few related information for alert notification to Email,syslog , snmp or other Log forwarding:

Email alerts,.

How to Configure Email Alerts for System Logs?

How to Setup Email Alerts

Example:

(A) The login information under SYSTEM logs will be "informational"

login-logs.JPG.jpg

(B) Create a server profile for SYSLOG and email notification.

syslog-1.JPG.jpg

(C)  Edit the "infomational" log settings under System>, add the configured SYSLOG server and email profile.

syslog-2.JPG.jpg

(D)  Set up a log forwarding profile under Object > Log forwarding

syslog-3.JPG.jpg

Hope this helps.

Thanks

Thank you for this very helpful information. but this isn't exactly what we are trying to figure out.

Correct me if I'm wrong but from what i understand on your comment, the traffic must first go through the policy.

what if the traffic is internal and it didn't pass through the sec policies.

thanks..

Hello Sir,

The above mentioned information is just an example. For SYSTEM logs, it does not require to have a security policy (assuming that the SYSLOG server is connected through management interface). Hence, you will get the login information whenever someone will try to login.

Thanks

Thank you for clearing that out. I will test this personally.

I appreciate your help.

-hartkently

  • 1 accepted solution
  • 3706 Views
  • 5 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!