Fortinet white logo
Fortinet white logo

External Systems Configuration Guide

Cisco VPN 3000 Gateway

Cisco VPN 3000 Gateway

What is Discovered and Monitored

Protocol Information Discovered Metrics Collected Used For
SNMP
Syslog

Event Types

In ADMIN > Device Support > Event Types, search for "cisco_vpn" to see the event types associated with this device.

Rules

There are no predefined rules for this device.

Reports

There are no predefined reports for this device.

Configuration

SNMP
  1. Log in to your device with administrative credentials.
  2. Go to Configuration > System > Management Protocols > SNMP Communities.
  3. Click Add.
  4. For Community String, enter public.
Syslog
  1. Go to Configuration > System > Events > Syslog Servers.
  2. Click Add.
  3. Enter the IP address of your FortiSIEM virtual appliance for Syslog Server.
  4. Add a syslog server with FortiSIEM IP Address.
Sample Parsed Cisco VPN 3000 Syslog Message

<189>18174 01/07/1999 20:25:27.210 SEV=5 AUTH/31 RPT=14  User [ admin ] Protocol [ Telnet ] attempted ADMIN logon. Status: <REFUSED> authentication failure

Settings for Access Credentials

Set these Access Method Definition values to allow FortiSIEM to communicate with your device.

Setting Value
Name <set name>
Device Type Cisco VPN 3K
Access Protocol See Access Credentials
Port See Access Credentials
Password config See Password Configuration

Cisco VPN 3000 Gateway

Cisco VPN 3000 Gateway

What is Discovered and Monitored

Protocol Information Discovered Metrics Collected Used For
SNMP
Syslog

Event Types

In ADMIN > Device Support > Event Types, search for "cisco_vpn" to see the event types associated with this device.

Rules

There are no predefined rules for this device.

Reports

There are no predefined reports for this device.

Configuration

SNMP
  1. Log in to your device with administrative credentials.
  2. Go to Configuration > System > Management Protocols > SNMP Communities.
  3. Click Add.
  4. For Community String, enter public.
Syslog
  1. Go to Configuration > System > Events > Syslog Servers.
  2. Click Add.
  3. Enter the IP address of your FortiSIEM virtual appliance for Syslog Server.
  4. Add a syslog server with FortiSIEM IP Address.
Sample Parsed Cisco VPN 3000 Syslog Message

<189>18174 01/07/1999 20:25:27.210 SEV=5 AUTH/31 RPT=14  User [ admin ] Protocol [ Telnet ] attempted ADMIN logon. Status: <REFUSED> authentication failure

Settings for Access Credentials

Set these Access Method Definition values to allow FortiSIEM to communicate with your device.

Setting Value
Name <set name>
Device Type Cisco VPN 3K
Access Protocol See Access Credentials
Port See Access Credentials
Password config See Password Configuration