SonicWall Firewall
Cyfin Reporter is installed on a
server, not on the SonicWall appliance

Logfile Setup
Logfile Type: SonicWALL Security Appliance
Configuration Notes
- Install a syslog daemon. Download Kiwi's syslog daemon.
- Make sure the machine running
the syslog daemon is running behind the firewall on the LAN.
- On the Sonicwall firewall Web
interface, go to Log screen. Then in the Syslog field, type
the IP address of the syslog daemon. Be sure to apply
the updates to the firewall.
- Edit the rules on the firewall
to allow inbound-to-outbound traffic on port 80 (http). Do
this at least once a week for http downloads of the list.
- You should now start seeing traffic
from the firewall on the syslog daemon. On the syslog services
go to the DNS setup and enable the Resolve Host option;
this is very critical to get Cyfin working.
- On the syslog daemon, create a
directory (i.e., c:\sonicwall\logs). Now, using the logging
to file option in the Kiwi setup configuration,
set up the syslog program to log the data into the log file.
- Install Cyfin and the syslog daemon on the
same server
and make sure that the reporting feature is targeting the logfile
used by the syslog.