Cisco ISR 4000 Family Routers Administrator Guidance
Page
55
of
66
Requirement
Management Action to
Log
Sample Log
FDP_RIP.2: Full residual
information protection
None
N/A
FIA_AFL.1
Configuring number of
failures.
Unlocking the user.
Feb 17 2013 16:14:47: %PARSER-5-
CFGLOG_LOGGEDCMD:
User:test_admin logged command:
aaa
local authentication attempts max-fail
[number of failures]
Feb 7 2013 02:05:41.953: %AAA-5-
USER_UNLOCKED: User user unlocked
by admin on vty0 (21.0.0.1)
FIA_PMG_EXT.1: Password
management
Setting length
requirement for
passwords.
Feb 15 2013 13:12:25.055: %PARSER-5-
CFGLOG_LOGGEDCMD: User:cisco
logged command: security passwords
min-length 15
FIA_PSK_EXT.1: Pre-
Shared Key Composition
Creation of a pre-shared
key.
Feb 15 2013 13:12:25.055: %PARSER-5-
CFGLOG_LOGGEDCMD: User:cisco
logged command:
crypto isakmp key
*****
FIA_UIA_EXT.1: User
identification and
authentication
Logging into TOE.
Jan 17 2013 05:05:49.460:
%SEC_LOGIN-5-LOGIN_SUCCESS:
Login Success [user: ranger] [Source:
21.0.0.3] [localport: 22] at 00:05:49 EST
Thu Jan 17 2013
FIA_UAU_EXT.2:
Password-based
authentication mechanism
None
N/A
FIA_UAU.7: Protected
authentication feedback
None
N/A
FIA_X509_EXT.1: X.509
Certificates
Generating a certificate.
Feb 17 2013 16:14:47: %PARSER-5-
CFGLOG_LOGGEDCMD:
User:test_admin logged command:
crypto key generate