Hi all I'm designing a solution where I need to forward syslog messages to 2 different servers (Cisco Works and a log correlation system). The messages will be sent from Cisco routers and PIXes to a box running syslog-ng that will forward the messages to the servers according to the facility and levels defined on filters. My question regards the origin of the messages as they will be seen by the end servers. Since both Cisco Works and the log correlation engine rely on the source IP to acknowledge and trigger alarms, will they see the syslog-ng box IP or the original IP address of the routers and PIXes? In other words will syslog-ng spoof the source IP addresses when forwarding the messages? Thanks in advance Fernando _____________________________________________________________________ INTERNET MAIL FOOTER A presente mensagem pode conter informação considerada confidencial. Se o receptor desta mensagem não for o destinatário indicado, fica expressamente proibido de copiar ou endereçar a mensagem a terceiros. Em tal situação, o receptor deverá destruir a presente mensagem e por gentileza informar o emissor de tal facto. --------------------------------------------------------------------- Privileged or confidential information may be contained in this message. If you are not the addressee indicated in this message, you may not copy or deliver this message to anyone. In such case, you should destroy this message and kindly notify the sender by reply email. ---------------------------------------------------------------------
participants (1)
-
Fernando Cardoso