SRX

last person joined: 9 hours ago 

Ask questions and share experiences about the SRX Series, vSRX, and cSRX.
  • 1.  HTTP logging with SRX

    Posted 03-22-2011 11:27

    Is it possible to log http requests (urls) of http traffic on the srx firewall? I know that traffic (RT_FLOW) logs are only ip/port based, but maybe it is possible somehow with utm content filtering? Or maybe webfilter logging? Or ANY other way? We desperately need this functionality...

     

    Regards,

    Pawel

     


    #logging
    #web.filtering


  • 2.  RE: HTTP logging with SRX
    Best Answer

    Posted 03-22-2011 21:31
    Yes, enabling web-filtering can log URLs in RTLog. This requires web-filtering license unless you have a redirect server such as Websense that you can use.

    -Richard


  • 3.  RE: HTTP logging with SRX

    Posted 03-29-2011 11:25

    Good news is that it works fine with juniper-local web filtering (ie it should work without web-filtering cp license, I have not tested that so far, but it should). HTTP method (GET, POST etc) is not logged, but url is. Neither are any other protocol elements - but bare get urls are logged fine.

    Bad news is that logging does not work well with surf-control-integrated web-filtering. The reason is probably url cache.. The first request for a certain url gets logged fine, but the log does not show subsequent requests for the same url (as checks are done from the cache I think). I have tried setting url cache size to zero - but it does not help. The device is running Junos 10.3R3.7.

    Have you got any ideas how to implement http traffic inspection/logging along with surf-control web-filtering?

     

    Regards,

    Pawel



  • 4.  RE: HTTP logging with SRX

    Posted 07-30-2011 14:28

    how did you get it working?



  • 5.  RE: HTTP logging with SRX

    Posted 09-04-2011 10:38

    We did not 😉

     

    Regards,

    Pawel



  • 6.  RE: HTTP logging with SRX

    Posted 09-04-2011 14:39

    Hi pmazurkeiwicz,

     

    The surf-control-integrated cache logging problem has been fixed and I know for a fact that it works fine in 10.4R6.

     

    Audab



  • 7.  RE: HTTP logging with SRX

    Posted 09-12-2011 07:22

    Thank you for information!

     

    Regards,

    Pawel



  • 8.  RE: HTTP logging with SRX

    Posted 07-03-2012 02:27
    Has this been done?
    Any kb or doc links to share?