Cisco ISR 4000 Family Routers Administrator Guidance
Page
54
of
66
Requirement
Management Action to
Log
Sample Log
Jan 24 2013 03:10:08.878: %GDOI-5-
KS_REKEY_TRANS_2_UNI: Group
getvpn transitioned to Unicast Rekey.ip
FCS_CKM_EXT.4:
Cryptographic key
zeroization
Manual key zeroization
Feb 17 2013 16:37:27: %PARSER-5-
CFGLOG_LOGGEDCMD:
User:test_admin logged command:crypto
key zeroize
FCS_COP.1(1):
Cryptographic operation (for
data encryption/decryption)
None
N/A
FCS_COP.1(2):
Cryptographic operation (for
cryptographic signature)
None
N/A
FCS_COP.1(3):
Cryptographic operation (for
cryptographic hashing)
None
N/A
FCS_COP.1(4):
Cryptographic operation (for
keyed-hash message
authentication)
None
N/A
FCS_RBG_EXT.1:
Cryptographic operation
(random bit generation)
None
N/A
FCS_IPSEC_EXT.1.1:IPSEC
Configuration of IPsec
settings: including mode,
security policy, IKE
version, algorithms,
lifetimes, DH group, and
certificates.
Feb 17 2013 16:14:47: %PARSER-5-
CFGLOG_LOGGEDCMD:
User:test_admin logged command:
crypto isakmp policy 1
FCS_SSH_EXT.1: SSH
Configuration of SSH
settings: including
certificates or passwords,
algorithms, host names,
users.
Feb 17 2013 16:14:47: %PARSER-5-
CFGLOG_LOGGEDCMD:
User:test_admin logged command:
ip ssh
version 2