Encrypted Syslog Servers in Common Criteria Mode

FastIron devices in any mode send the generated syslog messages in real time to the local log storage on the device and to a syslog server (only if a syslog server is configured and available).

A FastIron device running in Common Criteria operational mode queues the syslog messages if a syslog server is not available or configured for the device. This queue is not related to the local syslog messages store and it is cleared when the syslog messages in the queue are forwarded to the syslog server. The queue cannot hold more than 3,000 syslog messages. On reaching the maximum message limit, the device displays an error message and no further syslog messages are queued.

Parameters that are defined for syslog server connections, such as specifying the hold time for queued messages and traps when the device reloads or switches over, are applicable for encrypted syslog connections as well.

The following table summarizes the transitions to and from Common Criteria mode.

Syslog Server Connections during Transition to and from Common Criteria Mode

From

To Non-FIPS Mode

To FIPS Mode

To Common Criteria Operational Mode

Non-FIPS mode

Not applicable

No change. FIPS mode does not support encrypted syslog servers.

Both UDP-based and encrypted syslog server connections are allowed in CC Operational mode.

FIPS mode

No change

Not applicable

Both UDP-based and encrypted syslog server connections are allowed in CC Operational mode.

Common Criteria mode

All the SSL servers are removed. Non-FIPS mode does not support encrypted syslog server connections.

Not allowed. You must disable Common Criteria mode to revert to non-FIPS mode, and then re-enable FIPS mode. FIPS mode does not support encrypted syslog server connections.

Not applicable