Cisco ISR 4000 Family Routers Administrator Guidance
Page
45
of
66
Requirement
Auditable Events
Additional
Audit Record
Contents
Sample Record
AuditSessionID
000000000000000D001C2D92, CKN
24AA15376050334AE1EA9BE8A
1D0894B000000000000000000000
00000000000
FCS_MACSEC_EX
T.3.1
Creation
and
update of Secure
Association Key
Creation and
update times
For SAK (Security Association
Key) creation-
Mar 15 2016 12:54:49.937 IST: MKA-
EVENT 80e0.1dc6.3e7f/0016
C7000003:
Generation of new Latest SAK
succeeded (Latest AN=0, KN=1)...
For SAK (Security Association
Key) update –
Mar 15 2016 <
tel:2016
> 14:38:53.326
IST: %MKA-6-SAK_REKEY: (Gi0/1/0
: 10) MKA Session is beginning a SAK
Rekey (current Latest AN/KN 0/1, Old
AN/KN
0/1) for RxSCI f4cf.e298.ccb8/000a,
AuditSessionID CKN
10000000000000000000000000000000
00000000000000000000000000000000
FCS_IPSEC_EXT.1
Failure
to
establish an IPsec
SA.
Session
establishment with
peer
Reason
for
failure.
Entire packet
contents
of
packets
transmitted/rec
eived during
session
establishment
Initiation of IPSEC session (outbound):
Jun 20 07:42:26.823: ISAKMP (0):
received packet from 100.1.1.5 dport 500
sport 500 Global (N) NEW SA
Jun 20 07:42:26.823: ISAKMP: Created
a peer struct for 100.1.1.5, peer port 500
Jun 20 07:42:26.823: ISAKMP: New
peer created peer = 0x89C3879C
peer_handle = 0x8000000C
Jun 20 07:42:26.823: ISAKMP: Locking
peer struct 0x89C3879C, refcount 1 for
crypto_isakmp_process_block
Jun 20 07:42:26.823: ISAKMP: local
port 500, remote port 500
Jun 20 07:42:26.823: ISAKMP:(0):insert
sa successfully sa = 8C1C1FD4