跳至正文

Cisco ASA/FTD Integration

Overview

Cisco ASA and Firepower Threat Defense (FTD) provide stateful firewall, VPN, and next-generation IPS capabilities. KYRA MDR ingests ASA syslog and FTD eStreamer data for comprehensive threat visibility. Supports ASA 9.x and FTD 6.x/7.x.

Prerequisites

  • A KYRA MDR Collector installed and running
  • Cisco ASA or FTD with administrative access
  • Network connectivity from the device to the collector on port 514
  • For FTD: Firepower Management Center (FMC) access

Configuration

Configure syslog on Cisco ASA via CLI:

logging enable
logging host inside <collector-ip> TCP/514
logging trap informational
logging facility 23
logging device-id hostname
logging timestamp

For Cisco FTD via FMC:

  1. Navigate to Devices > Platform Settings
  2. Select the FTD device and click Syslog
  3. Add a syslog server with the collector IP and port 514
  4. Enable logging for security events
  5. Deploy the configuration

Collected Log Types

Log TypeDescriptionSecurity Use
ConnectionTCP/UDP connection eventsNetwork flow analysis, lateral movement
FirewallACL permit/deny decisionsPolicy enforcement monitoring
IPSSnort-based intrusion events (FTD)Exploit and attack detection
VPNIPsec and AnyConnect sessionsRemote access monitoring
FailoverHA state change eventsInfrastructure availability
AAAAuthentication and authorizationAccess control auditing

Troubleshooting

No syslog output: Verify logging enable is set and the logging trap level is at least informational. Check interface routing to the collector.

ASA message IDs missing: Ensure logging device-id hostname is configured so KYRA MDR can identify the source device.

FTD events not forwarding: Confirm the syslog server is added in FMC Platform Settings and the policy is deployed to the managed device.

Contact kyra@seekerslab.com for support.