Manual Chapter :
Configure IPsec event viewing on the BIG-IQ
Applies To:
Show Versions
BIG-IQ Centralized Management
- 5.3.0
How do I configure viewing IPsec event logs?
You can use BIG-IQ® Centralized Management to view IPsec events. To set up IPsec event log viewing, you need to:
- Configure the BIG-IP® devices that comprise the IPsec tunnel to send events to the data
collection device.
- Create a log publisher pool.
- Create a remote high-speed log destination for IPsec.
- Create a remote Syslog destination for IPsec.
- Configure a log publisher to send IPsec events to the BIG-IQ.
- Configure the BIG-IQ system to view
IPsec events.
- Import IPsec configuration settings from the BIG-IP device.
- Enable IPsec event collection.
After you complete these initial configuration tasks, you can view IPsec events on the BIG-IQ.
Create a log publisher pool
Creating a log publisher pool is
part of the sequence you perform to route IPsec events from the BIG-IP® device to your data collection device so that you can view these events
from the BIG-IQ®.
Important: Perform this task
on the BIG-IP devices that comprise the IPsec tunnel; not on the BIG-IQ.
Important: You must perform
these steps on both of the BIG-IP devices that comprise the IPsec tunnel.
The log publisher pool you created is
added to the pools list.
Create a remote high-speed log destination for IPsec
Before creating a remote high-speed
log destination for IPsec, you must create a log publishing pool.
Creating a remote high-speed log
destination is part of the sequence you perform to route IPsec events from the BIG-IP® device to your data collection device so that you can view
these events from the BIG-IQ®.
Important: Perform this task
on the BIG-IP devices that comprise the IPsec tunnel; not on the BIG-IQ.
Important: You must perform
these steps on both of the BIG-IP devices that comprise the IPsec tunnel.
Create a remote Syslog destination for IPsec
Before creating a remote Syslog log
destination for IPsec, you must create a log publishing pool and a high-speed log
destination for IPsec.
Creating a remote Syslog log
destination is part of the sequence you perform to route IPsec events from the BIG-IP® device to your data collection device so that you can view
these events from the BIG-IQ® system.
Important: Perform this task
on the BIG-IP devices that comprise the IPsec tunnel; not on the BIG-IQ.
Important: You must perform
these steps on both of the BIG-IP devices that comprise the IPsec tunnel.
Configure a log publisher to send IPsec events to the BIG-IQ
To send the IPsec event logs to the
data collection device, you must configure a publisher to send them to the IPsec Syslog
destination. This is the last task in the sequence you perform to route IPsec events
from the BIG-IP® device to your data collection device so that you
can view these events from the BIG-IQ®
Important: Perform this task
on the BIG-IP devices that comprise the IPsec tunnel; not on the BIG-IQ.
Important: You must perform
these steps on both of the BIG-IP devices that comprise the IPsec tunnel.
IPsec events will now route to the
data collection device.
To use the IPsec tunnel
configuration that you just completed on the BIG-IQ, you must import the settings for
this device to the BIG-IQ.
Import IPsec configuration settings from the BIG-IP device
Before you can import settings from a
managed device, you must have completed the configuration task on the BIG-IP® device. See Configure the BIG-IP device to send IPsec events to
your data collection device for details.
To manage an IPsec tunnel on BIG-IQ®, you need to import the settings configured on the BIG-IP
devices that reside on one each end of the tunnel.
Important: Perform this task
on the BIG-IQ for each of the BIG-IP devices that make up the IPsec tunnel.
The IPsec tunnel settings you
configured on the BIG-IP device are imported for the selected device.
Enable IPsec event collection
To view IPsec tunnel events on BIG-IQ®, you need to activate IPsec event collection for your data
collection device (DCD) cluster.
You can now view IPsec event logs
using the BIG-IQ user interface.