[syslog-ng]Syslog forwarding

Fernando Cardoso fernando.cardoso@whatevernet.com
Wed, 30 Oct 2002 20:31:40 -0000


Hi all

I'm designing a solution where I need to forward syslog messages to 2
different servers (Cisco Works and a log correlation system). The message=
s
will be sent from Cisco routers and PIXes to a box running syslog-ng that
will forward the messages to the servers according to the facility and
levels defined on filters.

My question regards the origin of the messages as they will be seen by th=
e
end servers. Since both Cisco Works and the log correlation engine rely o=
n
the source IP to acknowledge and trigger alarms, will they see the syslog=
-ng
box IP or the original IP address of the routers and PIXes? In other word=
s
will syslog-ng spoof the source IP addresses when forwarding the messages=
?

Thanks in advance

Fernando


_____________________________________________________________________
                      INTERNET MAIL FOOTER=20
A presente mensagem pode conter informa=E7=E3o considerada confidencial.
Se o receptor desta mensagem n=E3o for o destinat=E1rio indicado, fica
expressamente proibido de copiar ou endere=E7ar a mensagem a terceiros.
Em tal situa=E7=E3o, o receptor dever=E1 destruir a presente mensagem e p=
or
gentileza informar o emissor de tal facto.
---------------------------------------------------------------------
Privileged or confidential information may be contained in this
message. If you are not the addressee indicated in this message, you
may not copy or deliver this message to anyone. In such case, you
should destroy this message and kindly notify the sender by reply
email.
---------------------------------------------------------------------