Encrypted Syslog Servers in Common Criteria Mode

FastIron devices in any mode send the generated syslog messages in real time to the local log storage on the device. Local log storage can be configured and holds up to 4,000 messages by default. Old audits are overwritten in local log storage when the configured maximum is reached. FastIron devices in any mode also send generated syslog messages to a syslog server (only if a syslog server is configured and available).

A FastIron device running in Common Criteria operational mode queues the syslog messages if a syslog server is not available or configured for the device. This queue is not related to the local syslog messages store and it is cleared when the syslog messages in the queue are forwarded to the syslog server. The queue cannot hold more than 3,000 syslog messages. On reaching the maximum message limit, the device displays an error message and no further syslog messages are queued.

Parameters that are defined for syslog server connections, such as specifying the hold time for queued messages and traps when the device reloads or switches over, are applicable for encrypted syslog connections as well.

The following table summarizes the transitions to and from Common Criteria mode.

Syslog Server Connections during Transition to and from Common Criteria Mode

From

To Non-FIPS Mode

To FIPS Mode

To Common Criteria Operational Mode

Non-FIPS mode

Not applicable

No change. FIPS mode does not support encrypted syslog servers.

Both UDP-based and encrypted syslog server connections are allowed in CC Operational mode.

FIPS mode

No change

Not applicable

Both UDP-based and encrypted syslog server connections are allowed in CC Operational mode.

Common Criteria mode

All the SSL servers are removed. Non-FIPS mode does not support encrypted syslog server connections.

Not allowed. You must disable Common Criteria mode to revert to non-FIPS mode, and then re-enable FIPS mode. FIPS mode does not support encrypted syslog server connections.

Not applicable

Configuring the Logging Buffer for Local Storage in Common Criteria Mode

Use the logging buffered command to configure the size of the local syslog message buffer. By default, the buffer holds 4,000 messages. You can configure the buffer to hold from 1 through 4,000 messages. You can also configure the system to send a notification when the buffered messages reach a specified percentage of the maximum.

The no form of the logging buffered command returns the buffer size to its default value.

Note: Informational and debugging messages are not logged.
Note: When you change the logging buffer size, you must save the configuration and reload the system for the change to take effect. Any configuration change clears the logging buffer.

Examples:

The following example configures the local syslog buffer to retain 1,500 messages before overwriting.

ICX# configure terminal
ICX(config)# logging buffered 1500 

Syntax: logging buffered total_messages

The following example sets a percentage full threshold for buffered messages at 90%. When the threshold is exceeded, a system warning message is generated.

ICX(config)# logging buffered threshold 90

Syntax: logging buffered threshold percentage