1
00:00:06,300 --> 00:00:08,370
- Syslog is a protocol that's used

2
00:00:08,370 --> 00:00:11,250
by lots of different network devices

3
00:00:11,250 --> 00:00:16,250
that can output all the
log messages to a server.

4
00:00:17,548 --> 00:00:19,410
So it can output all that information

5
00:00:19,410 --> 00:00:21,300
right to your workstation.

6
00:00:21,300 --> 00:00:22,440
All right. We're logged in,

7
00:00:22,440 --> 00:00:26,010
and we'll go to the LOGS option here,

8
00:00:26,010 --> 00:00:30,057
and we'll see the recent log entries.

9
00:00:30,057 --> 00:00:31,470
You can see at the top here:

10
00:00:31,470 --> 00:00:34,407
Allowed configuration
authentication by .130.

11
00:00:34,407 --> 00:00:37,200
Well, 130 is the workstation
that I'm working at here.

12
00:00:37,200 --> 00:00:38,820
The one that's running this browser

13
00:00:38,820 --> 00:00:40,410
to my local machine.

14
00:00:40,410 --> 00:00:41,430
I just logged in.

15
00:00:41,430 --> 00:00:43,380
I just got authenticated.

16
00:00:43,380 --> 00:00:45,330
And if you look down the list here

17
00:00:45,330 --> 00:00:47,430
you'll see all kinds of good information.

18
00:00:47,430 --> 00:00:51,308
For example, blocked incoming UDP packet,

19
00:00:51,308 --> 00:00:54,049
blocked incoming UDP packet,

20
00:00:54,049 --> 00:00:57,120
blocked incoming TCP connection request.

21
00:00:57,120 --> 00:00:59,400
It happens all the time.

22
00:00:59,400 --> 00:01:02,550
I don't really care what you're running.

23
00:01:02,550 --> 00:01:04,830
You're most likely gonna
get hit by all kinds

24
00:01:04,830 --> 00:01:07,830
of people that are trying
to access your network

25
00:01:07,830 --> 00:01:10,890
or robots that are just
scanning your network.

26
00:01:10,890 --> 00:01:13,650
For example, somebody from 177.85.176.165

27
00:01:16,290 --> 00:01:19,500
was using port 53 to try
to connect to the router.

28
00:01:19,500 --> 00:01:22,830
Well, it got blocked because
the firewall's doing its job.

29
00:01:22,830 --> 00:01:24,210
And yeah, you may have guessed.

30
00:01:24,210 --> 00:01:26,342
This is, for this particular test network,

31
00:01:26,342 --> 00:01:31,342
this is my static IP out to the internet,

32
00:01:31,650 --> 00:01:32,610
which I will modify

33
00:01:32,610 --> 00:01:35,370
after all these videos have
been recorded, of course.

34
00:01:35,370 --> 00:01:37,290
But the key is, it's blocking it.

35
00:01:37,290 --> 00:01:41,310
And the firewall has logged
that this has happened.

36
00:01:41,310 --> 00:01:44,520
So if you get hit by somebody
a lot at the same IP address

37
00:01:44,520 --> 00:01:46,560
you could blacklist them or report them,

38
00:01:46,560 --> 00:01:48,630
or do whatever you wanna do about it.

39
00:01:48,630 --> 00:01:51,210
The key here though, is that it might be

40
00:01:51,210 --> 00:01:52,043
a bit of a hassle

41
00:01:52,043 --> 00:01:55,753
to use your browser to
connect to the router

42
00:01:55,753 --> 00:02:00,753
and to access the log
files in this manner.

43
00:02:00,870 --> 00:02:03,570
So, especially if you
have a lot of devices.

44
00:02:03,570 --> 00:02:06,630
So the great thing about Syslog is

45
00:02:06,630 --> 00:02:09,930
it can output all these log files

46
00:02:09,930 --> 00:02:11,940
to your Syslog Server software,

47
00:02:11,940 --> 00:02:14,310
which runs right at your workstation.

48
00:02:14,310 --> 00:02:16,020
And from that Syslog server

49
00:02:16,020 --> 00:02:18,288
you can access lots of different devices

50
00:02:18,288 --> 00:02:22,980
and lots of people can access
your Syslog server as well.

51
00:02:22,980 --> 00:02:25,110
So makes it a lot easier.

52
00:02:25,110 --> 00:02:26,880
And plus, it shows all the information

53
00:02:26,880 --> 00:02:28,890
in a real nice view,

54
00:02:28,890 --> 00:02:31,020
and you can do a lot of
searching and filtering,

55
00:02:31,020 --> 00:02:33,000
and it's a very good program to use.

56
00:02:33,000 --> 00:02:33,833
So what I wanna do is

57
00:02:33,833 --> 00:02:37,617
I wanna set up Syslog
to export this log file.

58
00:02:37,617 --> 00:02:40,863
So we'll do that from the TOOLS section.

59
00:02:41,842 --> 00:02:43,323
Go to Syslog.

60
00:02:44,370 --> 00:02:47,403
And we'll do enable
logging to a Syslog server.

61
00:02:48,240 --> 00:02:50,430
And I've already set that server up.

62
00:02:50,430 --> 00:02:54,270
I've already installed the
software, and it's .130.

63
00:02:54,270 --> 00:02:56,970
That's the local machine
that I'm working at here.

64
00:02:56,970 --> 00:02:58,293
We'll save the settings.

65
00:02:59,700 --> 00:03:02,940
And that'll start sending
out the information

66
00:03:02,940 --> 00:03:04,710
to that Syslog server.

67
00:03:04,710 --> 00:03:05,940
So we're done with the router.

68
00:03:05,940 --> 00:03:06,773
We don't have to do anything.

69
00:03:06,773 --> 00:03:08,010
We don't have to log into that router

70
00:03:08,010 --> 00:03:09,780
to see the logs anymore

71
00:03:09,780 --> 00:03:11,640
'cause they're gonna
automatically populate

72
00:03:11,640 --> 00:03:14,943
in the Syslog software,
which I'm gonna bring up now.

73
00:03:17,580 --> 00:03:20,010
Now I've already downloaded this software.

74
00:03:20,010 --> 00:03:22,212
I'm using Syslog Watcher, which I like.

75
00:03:22,212 --> 00:03:24,316
It's free program for now.

76
00:03:24,316 --> 00:03:26,310
I downloaded it, installed it

77
00:03:26,310 --> 00:03:30,270
and configured it to pull
information from the D-Link router

78
00:03:30,270 --> 00:03:33,030
10.254.254.1.

79
00:03:33,030 --> 00:03:34,560
Very easy to do.

80
00:03:34,560 --> 00:03:39,560
Once you do that, you can choose
how the software will work.

81
00:03:40,320 --> 00:03:41,790
Now, the way I set it up

82
00:03:41,790 --> 00:03:45,360
is as a local Syslog server.

83
00:03:45,360 --> 00:03:49,080
So it's storing all the Syslog information

84
00:03:49,080 --> 00:03:51,606
from this D-Link router,

85
00:03:51,606 --> 00:03:54,736
but you could also have
this information stored

86
00:03:54,736 --> 00:03:57,038
on another computer, on a remote computer

87
00:03:57,038 --> 00:03:59,400
and possibly, you know

88
00:03:59,400 --> 00:04:01,170
maybe that's your archival computer.

89
00:04:01,170 --> 00:04:02,820
Maybe it's a better type of computer

90
00:04:02,820 --> 00:04:05,910
that lots of admins can connect to.

91
00:04:05,910 --> 00:04:08,010
You might not want the
other admins connecting

92
00:04:08,010 --> 00:04:09,582
to your system.

93
00:04:09,582 --> 00:04:11,970
Or perhaps the IT Director has it running

94
00:04:11,970 --> 00:04:15,330
on a special computer and
all the other admins want

95
00:04:15,330 --> 00:04:17,488
to connect to that remote computer.

96
00:04:17,488 --> 00:04:19,634
And so you get a lot of options here.

97
00:04:19,634 --> 00:04:22,061
But I'm just running it locally.

98
00:04:22,061 --> 00:04:25,083
So I'm gonna choose manage
local Syslog server.

99
00:04:26,220 --> 00:04:30,060
We'll bring that guy up,
and we've already configured

100
00:04:30,060 --> 00:04:31,620
like I said, we've already
configured the router.

101
00:04:31,620 --> 00:04:34,320
It's 10.254.254.1.

102
00:04:34,320 --> 00:04:37,470
But you want to check a couple things

103
00:04:37,470 --> 00:04:40,470
within the configuration
when you first set it up

104
00:04:40,470 --> 00:04:42,330
and within your settings.

105
00:04:42,330 --> 00:04:44,670
Before I show that, what I wanna do is

106
00:04:44,670 --> 00:04:45,960
I wanna start the server

107
00:04:45,960 --> 00:04:49,860
and start it populating
information from the router

108
00:04:49,860 --> 00:04:51,180
'cause that's gonna take some time

109
00:04:51,180 --> 00:04:56,180
for actual logs to appear as they happen.

110
00:04:56,280 --> 00:04:57,963
So we'll start the server now.

111
00:05:01,830 --> 00:05:04,023
And it says down here service started.

112
00:05:04,920 --> 00:05:06,000
So that's good.

113
00:05:06,000 --> 00:05:08,640
And that's gonna take a
little bit to populate.

114
00:05:08,640 --> 00:05:10,780
So for now we'll go to the settings

115
00:05:11,670 --> 00:05:13,830
and we'll take a look at
the network interfaces.

116
00:05:13,830 --> 00:05:17,496
By default, when you use a Syslog server,

117
00:05:17,496 --> 00:05:20,520
the Syslog Server software now.

118
00:05:20,520 --> 00:05:24,227
This is what's running on
your local workstation here.

119
00:05:24,227 --> 00:05:26,460
It's gonna receive the syslogs,

120
00:05:26,460 --> 00:05:30,420
the syslog messages from
your router or your firewall

121
00:05:30,420 --> 00:05:33,870
or whatever device on port 514.

122
00:05:33,870 --> 00:05:36,630
And you can see some
messages are coming in now.

123
00:05:36,630 --> 00:05:38,700
But default port 514,

124
00:05:38,700 --> 00:05:42,330
and it uses a UDP transport mechanism,

125
00:05:42,330 --> 00:05:43,830
which is connection-less,

126
00:05:43,830 --> 00:05:46,770
which is fine for my purposes.

127
00:05:46,770 --> 00:05:51,192
But in a very, in a
high security situation

128
00:05:51,192 --> 00:05:53,460
connection-less might not be any good

129
00:05:53,460 --> 00:05:55,388
because you might
actually lose some packets

130
00:05:55,388 --> 00:05:58,830
in those non-guaranteed sessions.

131
00:05:58,830 --> 00:06:00,875
So you might want to use TCP.

132
00:06:00,875 --> 00:06:04,020
You might wanna have
guaranteed connectivity.

133
00:06:04,020 --> 00:06:06,930
And to do that, this
program uses port 1468.

134
00:06:06,930 --> 00:06:10,572
That might vary from
one program to the next.

135
00:06:10,572 --> 00:06:14,610
Also some of the proprietary
programs use their own port.

136
00:06:14,610 --> 00:06:17,790
They might not use port 514 by default.

137
00:06:17,790 --> 00:06:20,070
So that's gonna depend on the program.

138
00:06:20,070 --> 00:06:21,810
So always check that in the settings.

139
00:06:21,810 --> 00:06:25,238
But the default syslog port is 514.

140
00:06:25,238 --> 00:06:28,800
Connection-less UDP transport mechanism.

141
00:06:28,800 --> 00:06:30,630
So you always wanna check your settings.

142
00:06:30,630 --> 00:06:33,750
Make sure it's working properly
and configured properly.

143
00:06:33,750 --> 00:06:35,220
We know this is configured properly.

144
00:06:35,220 --> 00:06:37,670
It's grabbing information from .1

145
00:06:38,760 --> 00:06:41,550
and it's gonna keep on
grabbing the information

146
00:06:41,550 --> 00:06:43,170
as the logs come in,

147
00:06:43,170 --> 00:06:46,206
which is, basically, is
broken down into two things:

148
00:06:46,206 --> 00:06:50,010
who logged into the
router and what they do.

149
00:06:50,010 --> 00:06:52,200
And who's trying to connect to the router

150
00:06:52,200 --> 00:06:54,510
from the outside, from the internet.

151
00:06:54,510 --> 00:06:58,500
For example, the first
one that came in here

152
00:06:58,500 --> 00:07:02,400
is a blocked request and it shows you here

153
00:07:02,400 --> 00:07:04,980
blocked incoming TCP connection request

154
00:07:04,980 --> 00:07:06,510
from blah, blah, blah.

155
00:07:06,510 --> 00:07:09,663
And the information also
shows up on the bottom here,

156
00:07:10,710 --> 00:07:12,630
and you can see exactly what happened.

157
00:07:12,630 --> 00:07:14,580
Blocked incoming TCP connection.

158
00:07:14,580 --> 00:07:19,580
Requests from
222.185.198.158 on port 58106

159
00:07:21,210 --> 00:07:26,210
to my address, 64.121.172.56 on port 23.

160
00:07:27,480 --> 00:07:29,820
Well, they're basically trying
to telnet into the system.

161
00:07:29,820 --> 00:07:31,558
You know, they're using port 23.

162
00:07:31,558 --> 00:07:34,080
That's gonna be blocked by this firewall.

163
00:07:34,080 --> 00:07:36,330
That's a basic thing that, you know

164
00:07:36,330 --> 00:07:37,440
most firewalls are gonna block.

165
00:07:37,440 --> 00:07:40,560
So it did its job, but it's
good to know what happened

166
00:07:40,560 --> 00:07:42,633
and when, and who was trying to do it.

167
00:07:43,770 --> 00:07:46,380
You want to be able to
read these types of logs.

168
00:07:46,380 --> 00:07:48,840
You wanna understand
exactly what's happening

169
00:07:48,840 --> 00:07:50,880
with these types of logs.

170
00:07:50,880 --> 00:07:55,800
Definitely make sure that
you can run a Syslog server,

171
00:07:55,800 --> 00:07:59,820
pull information from your
router, your Soho device,

172
00:07:59,820 --> 00:08:02,640
your firewall, multiple
devices if you want.

173
00:08:02,640 --> 00:08:04,350
Because you can have, you know,

174
00:08:04,350 --> 00:08:06,724
multiple sources if you want.

175
00:08:06,724 --> 00:08:10,830
And make sure that you can
decipher these messages.

176
00:08:10,830 --> 00:08:15,252
Understand what these
messages are, what they mean.

177
00:08:15,252 --> 00:08:17,340
It's important to understand, you know

178
00:08:17,340 --> 00:08:21,840
the source IP address, the
source port and your IP address

179
00:08:21,840 --> 00:08:23,961
and the port that they
were trying to connect to

180
00:08:23,961 --> 00:08:28,260
and understand what these
possible attacks could be.

181
00:08:28,260 --> 00:08:30,510
For example, trying to
connect through telnet

182
00:08:30,510 --> 00:08:34,060
or trying to use a DNS
server to connect to you.

183
00:08:34,060 --> 00:08:36,300
Or possibly trying to connect

184
00:08:36,300 --> 00:08:39,210
through some type of Android
port or something like that.

185
00:08:39,210 --> 00:08:42,930
Just trying to find an
opening on your network.

186
00:08:42,930 --> 00:08:45,420
One vulnerability is all it takes.

187
00:08:45,420 --> 00:08:47,580
So, and it's amazing because you know

188
00:08:47,580 --> 00:08:52,230
if you look at any basic firewall
or, you know, Soho router

189
00:08:52,230 --> 00:08:55,470
that's out there, it's
gonna get hit every minute,

190
00:08:55,470 --> 00:08:57,300
two minutes, every five minutes,

191
00:08:57,300 --> 00:09:00,150
by some type of device
out on the internet.

192
00:09:00,150 --> 00:09:03,150
You know, constantly just
pounding away at all the computers

193
00:09:03,150 --> 00:09:04,680
it possibly can.

194
00:09:04,680 --> 00:09:06,060
So it's amazing to look at,

195
00:09:06,060 --> 00:09:08,760
but it's something that you
want to keep in mind here.

196
00:09:08,760 --> 00:09:10,320
And then of course you can import

197
00:09:10,320 --> 00:09:11,910
and export this information.

198
00:09:11,910 --> 00:09:14,250
You can filter this
information the way you want

199
00:09:14,250 --> 00:09:15,180
to find what you want

200
00:09:15,180 --> 00:09:18,360
'cause there's gonna be a
lot of logs as time goes on.

201
00:09:18,360 --> 00:09:23,360
And again, like I said, it's really easy.

202
00:09:23,370 --> 00:09:24,630
It's very manageable.

203
00:09:24,630 --> 00:09:27,210
It's very easy to work
with and it's a lot easier

204
00:09:27,210 --> 00:09:29,670
than logging into all
your different routers

205
00:09:29,670 --> 00:09:32,310
and firewalls and
connecting into the firmware

206
00:09:32,310 --> 00:09:35,280
with your browser and checking
the log files individually.

207
00:09:35,280 --> 00:09:39,423
You could check 'em all from
this one Syslog server screen.
