EasyManuals Logo
Home>Cisco>Firewall>Firepower 4110

Cisco Firepower 4110 User Manual

Cisco Firepower 4110
72 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #18 background imageLoading...
Page #18 background image
Cisco Preparative Procedures & Operational User Guide
© 2016 Cisco Systems, Inc. All rights reserved.
4.2 Auditable Events
The appliances that are part of the Cisco FP 4100 and 9300 System generate an audit record for each user
interaction with the web interface, and also record system status messages in the system log. For the CLI,
the appliance also generates an audit record for every action executed.
Each appliance generates an audit event for each user interaction with the web interface and CLI
command executed. Each event includes at least a timestamp, the user name of the user whose action
generated the event, a source IP, and text describing the event. The common fields are described in the
table below. The required auditable events are also provided in the table below.
Description
The date and time of the audit event.
The type of user.
The session ID associated with the session.
The type of action.
More information about the audit event including user, component (if
applicable), event type (success or failure), etc. See table below for
examples.
The component that is affected.
The user role associated with the user.
The system properties that were changed by the event.
SFR
Auditable
Event
Actual Audited Event
FAU_GEN.1
Startup and
shutdown
events
2
%FPRM-6-AUDIT:
[USERNAME][USERNAME][modification][web_45842_A][1385040][sys/svc-
ext/syslog/client-secondary][adminState(Old:disabled, New:enabled)][] Syslog
Remote Destination IP_ADDRESS modified
%FPRM-6-AUDIT:
[USERNAME][USERNAME][modification][web_42962_A][1383935][sys/svc-
ext/syslog/client-primary][adminState(Old:enabled, New:disabled)][] Syslog
Remote Destination IP_ADDRESS modified
FCS_HTTPS_EXT.1
Failure to
establish an
HTTPS
session.
See FCS_TLSS_EXT.1.
FCS_IPSEC_EXT.1
Failure to
%AUTHPRIV-6-SYSTEM_MSG: 05[IKE] IKE_SA test2[3] established
2
Actual date and time are not shown.

Table of Contents

Other manuals for Cisco Firepower 4110

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Cisco Firepower 4110 and is the answer not in the manual?

Cisco Firepower 4110 Specifications

General IconGeneral
BrandCisco
ModelFirepower 4110
CategoryFirewall
LanguageEnglish

Related product manuals