Support
Joined: 09 Oct 2002 Posts: 175 Location: Lausanne, Switzerland
|
Posted: Tue Jan 14, 03 11:52 Post subject: How can I know when tunnels are being attempted? |
|
|
By using the Custom Syslog functionality you can make filters on the INPUT and OUTPUT Filter tables to watch for IKE exchanges (using UDP port 500) or the movement of ESP/AH packets from known or unlisted IP addresses. This combined with a syslog server residing on your network can allow for notification of IPSec activity. |
|