Solved

how to audit routers for security

Posted on 2004-08-18
5
345 Views
Last Modified: 2010-04-17
how can i monitor and audit the commands entered into our cisco router? and also trace who entered them???
0
Comment
Question by:orcganir
5 Comments
 
LVL 8

Expert Comment

by:MarkDozier
ID: 11838209
use the syslog command. Your router documentation should cover the command or you can look it up on the cisco site.

0
 

Author Comment

by:orcganir
ID: 11838307
actually, what i was looking for is a way to log the commands entered, by who and when..
i alredy have an existing syslog setup. i use RADIUS for authentication but its accounting features are somewhat limited.. thanks
0
 
LVL 3

Expert Comment

by:fatlad
ID: 11838688
With Radius or TACACS command accounting you should be able to have all the commands issued by user. Check out

http://www.cisco.com/en/US/products/sw/iosswrel/ps1835/products_configuration_guide_chapter09186a00800ca7aa.html#32118

Should tell you how to set it up

Good Luck

FatLad
0
 
LVL 3

Expert Comment

by:fatlad
ID: 11838697
Sorrt just noticed that Cisco does not support RADIUS accounting, only TACACS+
0
 
LVL 4

Accepted Solution

by:
bfarmer earned 500 total points
ID: 11840394
We use TACACS+ for this purpose.

If you don't have TACACS+ check out the following:

http://www.cisco.com/en/US/products/sw/iosswrel/ps5207/products_feature_guide09186a00801d1e81.html

Looks like Cisco has introduced a configuration change log as of 12.3(4)T.
0

Featured Post

Building an interactive eFuture classroom

Watch and learn how ATEN provided a total control system solution including seamless switching matrix switch, HDBaseT extenders, PDU, lighting control to build an interactive eFuture classroom.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Ping Through ASA Firewall 6 55
How to restrict all websites and allow only citrix website 5 76
Running a 2nd company from the same location 3 69
Choice of router 8 39
While it is possible to put two routes in place with the secondary having a higher metric, this may not always work. In the event of a failure that does not bring down the physical interface on the router the primary route is not removed. There is a…
The Cisco RV042 router is a popular small network interfacing device that is often used as an internet gateway. Network administrators need to get at the management interface to make settings, change passwords, etc. This access is generally done usi…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

679 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question