Event Manager for Cisco Firewalls (Legacy)
Date Published: May 2009
Event Manager for Firewalls allows you to monitor Cisco Secure PIX, ASA, and FWSM Firewalls. By detecting, alerting on, and automatically responding to critical events in real-time, this module helps indicate, correct, and prevent possible external intrusions, attacks, and configuration problems.
Event Manager for Firewalls provides embedded expertise so you can proactively manage Cisco firewalls and identify issues before they become critical. This module increases the security, availability, and performance of Cisco firewalls.
Event Manager for Firewalls monitors syslog messages generated by Cisco firewalls. Event Manager for Firewalls also highlights events that may indicate configuration changes or external attacks, so you can quickly take corrective or preventive actions. For example, Event Manager for Firewalls enables you to perform the following tasks:
This release supports the following products:
Why Install This Module?
Event Manager for Cisco Firewalls provides support for received data that contains Internet Protocol version 6 (IPv6) addresses when used with Security Manager 6.0 Service Pack 2. To use this feature, you do not need to install a new version of Event Manager for Cisco Firewalls, but you must install Security Manager 6.0 Service Pack 2. For more information about how Security Manager supports IPv6, see the Security Manager 6.0 Service Pack 2 documentation.
Improvements are made in direct response to suggestions from our customers. We thank you for your time and valuable input. We hope you continue to help us ensure our products meet all your needs.
The following table lists additional requirements for a Windows agent acting as the agent for Cisco firewalls. For more information about agent requirements, see the Installation Guide for NetIQ Security Manager.
Installing This Module
You can install this module using the Module Installer. After you install the module, run the Configuration Wizard to configure the module. For more information about how to follow the Configuration Wizard, click the Help icon in the lower left of the wizard.
Configuring the Agent
To configure the Windows agent, add the name and IP address of the Cisco firewall device to the Hosts file on the Windows agent computer. For more information about the Hosts file, see the Windows documentation.
Configuring Cisco Firewall Devices
You can configure one or more Cisco firewall devices to communicate effectively with the Windows agent computer.
To configure a Cisco firewall device:
NetIQ Corporation strives to ensure our products provide quality solutions for your enterprise software needs. The following issues are currently being researched. If you need further assistance with any issue, please contact Technical Support.
Device ID Cannot Have Three Characters
Due to limitations in regex parsing for this release, the Device ID can have less than three characters or more than three characters, but not exactly three characters.
Data Not Properly Generated
If you install or make configuration changes to a previous version of this module after February 22, 2008, upgrade to this release will fail without errors. For information about how to upgrade in this situation, see the NetIQ Technical Support Knowledge Base article NETIQKB70933 on the NetIQ Technical Support Site at www.netiq.com/support.
Configuration Not Preserved after Upgrade
In some environments, configuration information is not maintained after you upgrade to this release. The upgrade removes all configuration information in some cases, but only partial information in other situations. After you upgrade, run the configuration wizard and verify all information.
Incorrect Address or Interface Name
Events will not be properly interpreted if an interface name on the firewall includes a colon or space.
Previous Data Not Formatted Correctly in Forensic Report
With this release, Security Manager records data differently than in previous releases. Reports in this release do not properly display data gathered using the old structure. When you perform a forensic query, only use data gathered using this release.
Forensic Reports Do Not Run
Forensic reports run with a previous version will not return data collected with this release. To run the forensic reports on data collected with this release,
back up, and then delete the forensics configuration file. By default, the forensics configuration file is
Incorrect Platform Name in Summary Reports
Summary reports generated with this release incorrectly specify
Incorrect Computer Group Name
If you are upgrading from a previous version, the computer group is named
Please contact us with your questions and comments. We look forward to hearing from you.
For detailed contact information, see the Support Contact Information Web site.
NetIQ Domain Migration Administrator is protected by United States Patent No(s): nnnnnnnn, nnnnnnnn, nnnnnnnn.
THIS DOCUMENT AND THE SOFTWARE DESCRIBED IN THIS DOCUMENT ARE FURNISHED UNDER AND ARE SUBJECT TO THE TERMS OF A LICENSE AGREEMENT OR A NON-DISCLOSURE AGREEMENT. EXCEPT AS EXPRESSLY SET FORTH IN SUCH LICENSE AGREEMENT OR NON-DISCLOSURE AGREEMENT, NETIQ CORPORATION PROVIDES THIS DOCUMENT AND THE SOFTWARE DESCRIBED IN THIS DOCUMENT "AS IS" WITHOUT WARRANTY OF ANY KIND, EITHER EXPRESS OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. SOME STATES DO NOT ALLOW DISCLAIMERS OF EXPRESS OR IMPLIED WARRANTIES IN CERTAIN TRANSACTIONS; THEREFORE, THIS STATEMENT MAY NOT APPLY TO YOU.
This document and the software described in this document may not be lent, sold, or given away without the prior written permission of NetIQ Corporation, except as otherwise permitted by law. Except as expressly set forth in such license agreement or non-disclosure agreement, no part of this document or the software described in this document may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, electronic, mechanical, or otherwise, without the prior written consent of NetIQ Corporation. Some companies, names, and data in this document are used for illustration purposes and may not represent real companies, individuals, or data.
This document could include technical inaccuracies or typographical errors. Changes are periodically made to the information herein. These changes may be incorporated in new editions of this document. NetIQ Corporation may make improvements in or changes to the software described in this document at any time.
© 2009 NetIQ Corporation. All Rights Reserved.
U.S. Government Restricted Rights: If the software and documentation are being acquired by or on behalf of the U.S. Government or by a U.S. Government prime contractor or subcontractor (at any tier), in accordance with 48 C.F.R. 227.7202-4 (for Department of Defense (DOD) acquisitions) and 48 C.F.R. 2.101 and 12.212 (for non-DOD acquisitions), the government's rights in the software and documentation, including its rights to use, modify, reproduce, release, perform, display or disclose the software or documentation, will be subject in all respects to the commercial license rights and restrictions provided in the license agreement.
Check Point, FireWall-1, VPN-1, Provider-1, and SiteManager-1 are trademarks or registered trademarks of Check Point Software Technologies Ltd.
ActiveAgent, ActiveAnalytics, ActiveAudit, ActiveReporting, ADcheck, Aegis, AppAnalyzer, AppManager, the cube logo design, Change Administrator, Change Guardian, Compliance Suite, Directory and Resource Administrator, Directory Security Administrator, Domain Migration Administrator, Exchange Administrator, File Security Administrator, Group Policy Administrator, Group Policy Guardian, Group Policy Suite, IntelliPolicy, Knowing is Everything, Knowledge Scripts, Mission Critical Software for E-Business, MP3check, NetConnect, NetIQ, the NetIQ logo, the NetIQ Partner Network design, Patch Manager, PSAudit, PSDetect, PSPasswordManager, PSSecure, Risk and Compliance Center, Secure Configuration Manager, Security Administration Suite, Security Analyzer, Security Manager, Server Consolidator, VigilEnt, Vivinet, Vulnerability Manager, Work Smarter, and XMP are trademarks or registered trademarks of NetIQ Corporation or its subsidiaries in the United States and other jurisdictions. All other company and product names mentioned are used only for identification purposes and may be trademarks or registered trademarks of their respective companies.