Nortel 3050 Command Reference Manual page 128

Vpn gateway
Hide thumbs Also See for 3050:
Table of Contents

Advertisement

128 Command Reference
Table 34
Pool Settings Menu Options (/cfg/ssl/server/adv/pool) (cont'd.)
Command Syntax and Usage
dis
/cfg/ssl/server <id> /adv/traflog Traffic Syslog
Configuration
[Traffic Log Settings Menu]
sysloghost - Set syslog host IP
udpport - Set syslog portnumber
priority - Set syslog priority
facility- Set syslog facility
ena - Enable traffic UDP syslog logging
The Traffic Log Settings menu is used for configuring a syslog server,
to which UDP syslog messages for all HTTP requests handled by the
currently selected virtual SSL server, can be sent. Enabling traffic logging
through syslog messages will generate a substantial amount of network
traffic, and also place additional CPU load on each NVG device in the
cluster. Besides, syslog servers are not generally intended for this type of
log messages, and the syslog server might therefore not be able to cope
with the amount of syslog messages generated within a cluster of multiple
NVG devices. In environments where traffic logging must be performed on
the SSL terminating device itself due to laws or regulations, traffic logging
through syslog messages can be used. It can also be used temporarily
for debugging purposes. This setting will generate traffic; therefore it is
recommended that you set up syslog on the backend server if possible.
In general, it is therefore recommended that traffic logging is performed
on the backend web servers instead. The traffic logging performed by
backend web servers can be enhanced by configuring the VPN Gateway
to add certain HTTP headers. For more information about available
extra HTTP headers, see the HTTP Settings menu on
/server/http HTTP Settings Configuration" (page
Below is an example of a syslog message generated on an NVG device:
Mar 8 14:14:33 192.168.128.24 <ISD-SSL>:
192.168.128.189 TLSv1/SSLv3 DES-CBC3-SHA "GET / HTTP/1.0"
To access the Traffic Log Settings menu, the selected virtual SSL server
must be set to either the http type or the portal type.
Copyright © 2007 Nortel Networks
.
Disables pooling of server side sockets for the selected virtual SSL
server.
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007
"/cfg/vpn <id>
272).

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

3070Nvg 3050Nvg 3070Svm 10001000 con?guration guide

Table of Contents