Encrypted Syslog Servers in Common Criteria Mode
A FastIron device running in Common Criteria operational mode queues the syslog messages if a syslog server is not available or configured for the device. This queue is not related to the local syslog messages store and it is cleared when the syslog messages in the queue are forwarded to the syslog server. The queue cannot hold more than 3,000 syslog messages. On reaching the maximum message limit, the device displays an error message and no further syslog messages are queued.
Parameters that are defined for syslog server connections, such as specifying the hold time for queued messages and traps when the device reloads or switches over, are applicable for encrypted syslog connections as well.
The following table summarizes the transitions to and from Common Criteria mode.
Syslog Server Connections during Transition to and from Common Criteria Mode
Configuring the Logging Buffer for Local Storage in Common Criteria Mode
Use the logging buffered command to configure the size of the local syslog message buffer. By default, the buffer holds 4,000 messages. You can configure the buffer to hold from 1 through 4,000 messages. You can also configure the system to send a notification when the buffered messages reach a specified percentage of the maximum.
The no form of the logging buffered command returns the buffer size to its default value.
The following example configures the local syslog buffer to retain 1,500 messages before overwriting.
ICX# configure terminal ICX(config)# logging buffered 1500
Syntax:
logging buffered
total_messages
The following example sets a percentage full threshold for buffered messages at 90%. When the threshold is exceeded, a system warning message is generated.
ICX(config)# logging buffered threshold 90