Cisco ISR 4000 Family Routers Administrator Guidance
Page
47
of
66
Requirement
Auditable Events
Additional
Audit Record
Contents
Sample Record
Termination
of
IPSEC
session
(outbound-initiated)
.Jun 19 21:09:49.619: IPSEC(delete_sa):
deleting SA,
(sa) sa_dest= 100.1.1.5, sa_proto= 50,
sa_spi= 0x3C81B171(1015132529),
sa_trans= esp-aes esp-sha-hmac ,
sa_conn_id= 62
sa_lifetime(k/sec)= (4608000/28800),
(identity) local= 100.1.1.1:0, remote=
100.1.1.5:0,
local_proxy=
10.1.1.0/255.255.255.0/256/0,
remote_proxy=
12.1.1.0/255.255.255.0/256/0
Jun
19
21:10:37.575:
ISAKMP:(2034):purging
node
-
506111676
.Jun 19 21:10:39.615:
ISAKMP:(2034):purging
node
-
22679511
.Jun 20 04:46:14.789:
IPSEC(lifetime_expiry): SA lifetime
threshold reached, expiring in 1412
seconds
Failure to establish an IPSEC session
(outbound-initiated)
Jun 19 11:12:33.905: %CRYPTO-5-
IKMP_AG_MODE_DISABLED:
Unable to initiate or respond to
Aggressive Mode while disabled
FCS_SSHS_EXT.1
Failure
to
establish an SSH
session
Reason
for
failure.
Failure to establish a SSH Session.
IP address of remote host
Reason for failure.
GENERIC EXAMPLE: Jun 18 2012
11:19:06
UTC:
%SEC_LOGIN-4-