Sunday, March 14, 2021

Forwarding logs to a postfix mail server, from PA VM (Software Version 9.1.7 GlobalProtect Agent 5.2.4)

Hi all im not too sure whether this has been done before or not, or achievable. But im currently left scratching my head. Can anyone shed any light with how they might go about having email log forwarding setup to a customer's own hosted postfix server (smtp/port 25) in the 10.1.x local range on their network?

We want to send custom generated reports of permitted individuals logging in the fwall, containing the duration of their sessions.

To give you some background, where I work is an MSP where we provide network/connectivity to lots of different customers. This customer has a few CPE sites with some fiber/dsl lines, as well as a main dual PA VM (which i believe acts as a breakout firewall for mpls connections/internet and so on).

I'd be interested to see how you guys would do it, and to take away any guidance where possible. So far we are a bit stumped on the part that asks 'from' and then 'to' in the email server profile settings, seen as the only info we have from our customer is:

The customer's postfix is locked down to source I.P addresses so will need to know the source IP of the SMTP requests? (I am guessing this the source from where the PA will send out the logs?)
Server address: 10.1.0.46
Server authentication: none
Server port: 25
[customer.customer@technology.com](mailto:customer.customer@technology.com) (this is just a fake email, do not want to expose our customers real one. We want to include this example address into the recipients in the email profile settings, so that he too can receive copies, not sure why lol)

Please if you need more info, just ask. Don't feel as though you have to read minds, I am not really great with PA's so some specifics might have been left out...

Thanks!



No comments:

Post a Comment