Solved

Need to be able to see who logged in, when and what changes they made on Cisco Routers, Switches and FWs (ASA).

Posted on 2014-10-27
6
181 Views
Last Modified: 2014-10-27
Need to be able to see who logged in, when and what changes they made on Cisco Routers and Switches. I need to keep this information for a long period of time. Is there a way of doing this?

Thank you,
0
Comment
Question by:dsterling
  • 3
  • 2
6 Comments
 
LVL 17

Expert Comment

by:pjam
ID: 40406793
Cisco Network Assistant is a free app that contains a Security Wizard:
Have you installed that?  Take a look at that to see if it does what you want.
Cisco Network Assistant
0
 
LVL 50

Expert Comment

by:Don Johnston
ID: 40406841
Sounds like what you're looking for is AAA (Authorization, Authentication & Accounting).

http://www.cisco.com/c/en/us/td/docs/ios/12_2/security/configuration/guide/fsecur_c/scfaaa.html
0
 

Author Comment

by:dsterling
ID: 40406991
This doesn't let me see what changes they may of made for example: A Network Admin logs into a Cisco router and changes an ACL incorrectly, the Network admin goes on vacation or leaves the company. I need to see who made the change and what is was so it can be quickly fixed. Also we have to keep close track of authorized and unauthorized changes to the network.
0
PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

 
LVL 50

Accepted Solution

by:
Don Johnston earned 500 total points
ID: 40407129
This doesn't let me see what changes they may of made
I don't know who this was directed at...

But with AAA and regular configuration backups, it's pretty easy to see who changed the config and what was changed.  You can also use Configuration Change Notification and Logging.
0
 

Author Comment

by:dsterling
ID: 40407190
Couldn't this be viewed in the Cisco ACS server device also?
0
 

Author Closing Comment

by:dsterling
ID: 40407237
What I was looking for, great answer.
0

Featured Post

Scale it in WD Gold

With up to ten times the workload capacity of desktop drives, WD Gold hard drives employ advanced technology to deliver among the best in reliability, capacity, power efficiency and performance.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
ASA Deny No Connection PSH ACK, Traffic is dropped 10 65
SSH over http/https 8 104
What is a hashed password and/or MD5? 5 60
RDP ISR4321 Cisco Router 7 23
How to set-up an On Demand, IPSec, Site to SIte, VPN from a Draytek Vigor Router to a Cyberoam UTM Appliance. A concise guide to the settings required on both devices
You may have a outside contractor who comes in once a week or seasonal to do some work in your office but you only want to give him access to the programs and files he needs and keep privet all other documents and programs, can you do this on a loca…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

919 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

14 Experts available now in Live!

Get 1:1 Help Now