Configuring a Logging Host for NDcPP

  1. Configure a logging host with the local or remote IP address of the syslog server and its remote port number. On the same line, specify a pre-configured SSL profile.
    device# configure terminal
    device(config)# logging host < ip-address | server-name > ssl-port < port-number > profile < profile-name >
    

    Syntax: logging host { ip-address | server-name } ssl-port port-number profile profile-name

    When audit logs are generated, the FastIron device establishes a secure TLS tunnel.

    During the handshake with the server, the FastIron device receives the server certificate and obtains validation for the certificate from the CA server through the PKI infrastructure.

    If validation is successful, the handshake continues to look for the client certificate. If the server has requested a client certificate, the FastIron device sends the client certificate, and the server validates it using Verify protocol logic.

    If the client and server certificate validations are successful, the TLS tunnel is established, and audit logs are sent to the server over the secure and trusted tunnel. Subsequent log messages use the established TLS tunnel.

The following example configures a logging host with an IP address of 192.168.10.10. Its SSL port is 5002, and it uses the profile tls03.

device# configure terminal
device(config)# logging host 192.168.10.10 ssl-port 5002 profile tls03