Forum Discussion

EvilRootSa_2832's avatar
EvilRootSa_2832
Icon for Nimbostratus rankNimbostratus
Nov 02, 2009

Viewing Layer 2-4 via syslog

LTM

 

Bigip v.9.4.8

 

 

Is there a way to view Layer 2-4 traffic via syslog? i only see layer 7 traffic and that is because of the modifications of ssl.conf. Right now, my client is using the Bigp as a firewall and Im trying to have them move away from that. But the first thing I need to do is see how traffic comes and goes in the F5 so that I can create a rule baste. Any ideas?

 

 

EvilRootSa

1 Reply

  • How is the layer 2-4 traffic passing through LTM? If it's with a virtual server, you can use an iRule like this:

     

     

    http://devcentral.f5.com/Wiki/default.aspx/iRules/LogHttpTcpUdpToSyslogng.html

     

     

    If it's a SNAT, I'm not sure there is an efficient way. Outputting tcpdump to a text file would be a horrendous option, but could work depending on how much throughput there is and whether you're able to isolate the traffic via filters.

     

     

    Aaron