Link to home
Start Free TrialLog in
Avatar of Dragon0x40
Dragon0x40

asked on

Monitor another user on a Router or Switch

If two or more users are logged into a router or switch can you watch what they are typing and getting from show commands?

What commands would do that?
ASKER CERTIFIED SOLUTION
Avatar of luc_roy
luc_roy
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of Dragon0x40
Dragon0x40

ASKER

thanks luc roy and EDincer,

Someone at work said they were watching me as a made a change to a router and I was wondering what they meant. Maybe I will ask!

Maybe show user to see if I am idle and when the idle timer goes to 0 then do a sh run and see what changed?

Unless you know what the planned changes are then it might be tough but I guess you could suck up the config into a text editor and use some kind of diff command to see the differences.
Something like solar winds would tell them when you made a change.  It's just no live.  Also if someone says they are watching you it might be spyware or even a camera.
The change audit application of Cisco LMS lets you track and report network changes.

The change audit log fo LMS contains all the change that inventory manager, software manager and configuration manager applications discover. Every time one of these LMS applications detects a change (syslog message,snmp trap ), it`s sends a change record to the change audit service with details who made the change (possible in combination with cisco AAA security), when the change occoured and what type of the change occoured.

You can set up a syslog configuration in the DFM module of LMS for the real time monitoring.
if thye are using user base access, AAA or something like that.  but  again that is not a live feed, it is bases on when the changes are written to the router.
I will ask the guy I work with how he was monitoring what I was doing on the router.

I just thought maybe you could monitor another users session but apparently not.

Sometimes I try to figure things out on my own so I don't ask so many questions at work.
it's the best way to do things, I always want to figure things out off site.

Good luck.
My colleague was connected to the same router I was via telnet and repeatedly running the "sh run" command and looking for the changes that I was putting into the router.

He could not see what I was typing at the cli.