Cisco ASA/FTD Integration
Overview
Cisco ASA and Firepower Threat Defense (FTD) provide stateful firewall, VPN, and next-generation IPS capabilities. KYRA MDR ingests ASA syslog and FTD eStreamer data for comprehensive threat visibility. Supports ASA 9.x and FTD 6.x/7.x.
Prerequisites
- A KYRA MDR Collector installed and running
- Cisco ASA or FTD with administrative access
- Network connectivity from the device to the collector on port 514
- For FTD: Firepower Management Center (FMC) access
Configuration
Configure syslog on Cisco ASA via CLI:
logging enablelogging host inside <collector-ip> TCP/514logging trap informationallogging facility 23logging device-id hostnamelogging timestampFor Cisco FTD via FMC:
- Navigate to Devices > Platform Settings
- Select the FTD device and click Syslog
- Add a syslog server with the collector IP and port 514
- Enable logging for security events
- Deploy the configuration
Collected Log Types
| Log Type | Description | Security Use |
|---|---|---|
| Connection | TCP/UDP connection events | Network flow analysis, lateral movement |
| Firewall | ACL permit/deny decisions | Policy enforcement monitoring |
| IPS | Snort-based intrusion events (FTD) | Exploit and attack detection |
| VPN | IPsec and AnyConnect sessions | Remote access monitoring |
| Failover | HA state change events | Infrastructure availability |
| AAA | Authentication and authorization | Access control auditing |
Troubleshooting
No syslog output: Verify logging enable is set and the logging trap level is at least informational. Check interface routing to the collector.
ASA message IDs missing: Ensure logging device-id hostname is configured so KYRA MDR can identify the source device.
FTD events not forwarding: Confirm the syslog server is added in FMC Platform Settings and the policy is deployed to the managed device.
Contact kyra@seekerslab.com for support.