Controllerless Networks

 View Only
last person joined: 2 days ago 

Instant Mode - the controllerless Wi-Fi solution that's easy to set up, is loaded with security and smarts, and won't break your budget
Expand all | Collapse all

How to send the blacklist log of user-role to syslog server?

This thread has been viewed 12 times
  • 1.  How to send the blacklist log of user-role to syslog server?

    Posted Jul 11, 2022 04:56 AM
    dear 
         i want to sent blacklist log of user-role to syslog server,what should I do?
    like the example :
        ip access-list session test
            user any udp 68 deny log blacklist 
    is it right to do ?



    ------------------------------
    leo ma
    ------------------------------


  • 2.  RE: How to send the blacklist log of user-role to syslog server?

    EMPLOYEE
    Posted Jul 11, 2022 06:26 AM
    Hi Leo, this discussion group is more around controller-less setups (such as Aruba Instant deployments) but it looks like you are configuring an Aruba Controller/Gateway. 

    In Instant this works with the standard monitoring/logging levels as default. I configured a syslog server and added a basic rule that would result in dynamic denylist of the client if they used DNS. Hopefully the monitoring is similar between controller based and Instant. Unfortunately my lab is not configured to test this simply for you. Your access-list does look correct however.


  • 3.  RE: How to send the blacklist log of user-role to syslog server?
    Best Answer

    EMPLOYEE
    Posted Jul 11, 2022 07:09 AM
    You can review the syslog reference guide here for ArubaOS 8.10: ArubaOS-8.10.0.0-Syslog-Reference-Guide.xlsx

    It looks like you'll see this under Security logging level Notice (124008), User Warning (501103), User Notice (522039), User Info (541001).


  • 4.  RE: How to send the blacklist log of user-role to syslog server?

    Posted Jul 11, 2022 07:51 AM
    thank you, i am try, this is aos 8 controller,

    ------------------------------
    leo ma
    ------------------------------