Sending syslog messages over a vpn tunnel

mgclark
Here to help

Sending syslog messages over a vpn tunnel

I've heard that Meraki strongly suggests to not send syslog traffic over a vpn tunnel.

 

I've not been able to find any documentation mentioning this. The only official docs I've found are these three.

 

Syslog Event Types and Log Samples

https://documentation.meraki.com/zGeneral_Administration/Monitoring_and_Reporting/Syslog_Event_Types...

 

Syslog Server Overview and Configuration

https://documentation.meraki.com/zGeneral_Administration/Monitoring_and_Reporting/Syslog_Server_Over...

 

Meraki Device Reporting - Syslog, SNMP and API

https://documentation.meraki.com/zGeneral_Administration/Monitoring_and_Reporting/Meraki_Device_Repo...

 

Has anyone noticed any performance hits to the MXs when sending syslog messages through a VPN tunnel with data and voice?

6 Replies 6
cmr
Kind of a big deal
Kind of a big deal

We send loads of syslogs over our SD-WAN VPN tunnels, haven't noticed it causing any issues and we run 50+ VoIP/video handsets at each site

Nash
Kind of a big deal

@cmr Do you have to do the trick with the firewall rule, or does it just go for you? Thank you.

cmr
Kind of a big deal
Kind of a big deal

It just worked for us!

Nash
Kind of a big deal


@cmr wrote:

It just worked for us!


This is a great answer, thank you! We're beginning to send syslog via VPN, assuming a vendor can tell which customer the traffic belongs to. The vendor originally wanted naked syslog over the internet. 😱

cmr
Kind of a big deal
Kind of a big deal

Now that is just ****** how can they not realise that is not a good idea? 😱

Nash
Kind of a big deal


@cmr wrote:

Now that is just ****** how can they not realise that is not a good idea? 😱


It's a managed security services provider that specializes in banks.

 

So, you know... it's reassuring.

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.