Cisco ISR 4000 Family Routers Administrator Guidance
Page
51
of
66
Requirement
Auditable Events
Additional
Audit Record
Contents
Sample Record
FPT_STM.1
Changes to the
time.
The old and
new values for
the time.
Origin of the
attempt (e.g.,
IP address).
Local Clock Update: CLOCKUPDATE:
System clock has been updated from
06:11:37 EDT Mon Dec 20 2010 to
06:10:00 EDT Tue Dec 20 2011,
configured from console by user on
console.
One audit record for NTP changing the
time:
Jun
20
09:52:39.622:
NTP
Core(NOTICE): Clock is synchronized.
FPT_RPL.1
Detected
replay
attempt
None.
*Jul 7 18:43:14.595: %MKA-3-
MKPDU_VALIDATE_FAILURE:
(Gi0/0/1 : 11) Validation of a MKPDU
failed for RxSCI 6412.25a1.a409/0009,
AuditSessionID
,
CKN
12340000000000000000000000000000
00000000000000000000000000000000
FPT_TUD_EXT.1
Initiation
of
update. result of
the update attempt
(success
or
failure)
No additional
information.
Use of the “upgrade” command.
*Jul 10 11:04:09.179: %PARSER-5-
CFGLOG_LOGGEDCMD:
User:cisco logged command:upgrade
*Jul 10 11:04:09.179: %PARSER-5-
CFGLOG_LOGGEDCMD:
User:cisco logged command:copy tftp
….
*Jul 10 11:04:09.179: %PARSER-5-
CFGLOG_LOGGEDCMD:
User:cisco logged command:reload
FPT_TST_EXT.1
Indication
that
TSF self-test was
completed.
Any additional
information
generated
by
the
tests
beyond
“success” or
“failure”.
Jan 23 2013 06:53:24.570: %CRYPTO-
6-SELF_TEST_RESULT: Self test info:
(Self test activated by user: admin)
Jan 23 2013 06:53:24.670: %CRYPTO-
6-SELF_TEST_RESULT: Self test info:
(Software checksum ...
passed)
FPT_TST_EXT.2
Failure of self-test
Reason
for
failure
(including
identifier
of
Cause: c3m_set_fips_mode, Fatal Fault,
FIPS POST Failure requested by: Process