<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Difference between %SSH-5-SS2_USERAUTH and %SEC_LOGIN-5-LOGIN_SUCCESS and %SSH-5-SS2_SESSION in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/difference-between-ssh-5-ss2-userauth-and-sec-login-5-login/m-p/4283906#M565166</link>
    <description>&lt;P&gt;Good question: I tested in the lab on a switch that was not TACACS+ enabled, and another one that was TACACS+ enabled. Each time the same message.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Local auth (i.e. no RADIUS or TACACS+ was used)&lt;/P&gt;
&lt;PRE&gt;011961: Feb  1 20:40:13.146: %SEC_LOGIN-5-LOGIN_SUCCESS: Login Success [user: svc-dnac] [Source: 172.31.25.26] [localport: 22] at 20:40:13 UTC Mon Feb 1 2021
&lt;/PRE&gt;
&lt;P&gt;And then TACACS+&lt;/P&gt;
&lt;PRE&gt;032021: Feb  1 2021 20:37:59.481 UTC: %SEC_LOGIN-5-LOGIN_SUCCESS: Login Success [user: admin-biera] [Source: 172.31.25.26] [localport: 22] at 06:37:59 AEST Tue Feb 2 2021&lt;/PRE&gt;
&lt;P&gt;Do you get those two different messages from the same switch?&amp;nbsp; Perhaps it's from the console login (I can't test that - not on-site)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 01 Feb 2021 20:43:44 GMT</pubDate>
    <dc:creator>Arne Bier</dc:creator>
    <dc:date>2021-02-01T20:43:44Z</dc:date>
    <item>
      <title>Difference between %SSH-5-SS2_USERAUTH and %SEC_LOGIN-5-LOGIN_SUCCESS and %SSH-5-SS2_SESSION</title>
      <link>https://community.cisco.com/t5/network-access-control/difference-between-ssh-5-ss2-userauth-and-sec-login-5-login/m-p/4283876#M565157</link>
      <description>&lt;P&gt;As stated above, I would like to know the differences between the above event messages and if there is a chance that each of those event can be generated from a one user login. I understand what SSH, User authentication, and session is... but, when do this events actually generated?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Feb 2021 20:05:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/difference-between-ssh-5-ss2-userauth-and-sec-login-5-login/m-p/4283876#M565157</guid>
      <dc:creator>CarlosColon2948</dc:creator>
      <dc:date>2021-02-01T20:05:14Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between %SSH-5-SS2_USERAUTH and %SEC_LOGIN-5-LOGIN_SUCCESS and %SSH-5-SS2_SESSION</title>
      <link>https://community.cisco.com/t5/network-access-control/difference-between-ssh-5-ss2-userauth-and-sec-login-5-login/m-p/4283906#M565166</link>
      <description>&lt;P&gt;Good question: I tested in the lab on a switch that was not TACACS+ enabled, and another one that was TACACS+ enabled. Each time the same message.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Local auth (i.e. no RADIUS or TACACS+ was used)&lt;/P&gt;
&lt;PRE&gt;011961: Feb  1 20:40:13.146: %SEC_LOGIN-5-LOGIN_SUCCESS: Login Success [user: svc-dnac] [Source: 172.31.25.26] [localport: 22] at 20:40:13 UTC Mon Feb 1 2021
&lt;/PRE&gt;
&lt;P&gt;And then TACACS+&lt;/P&gt;
&lt;PRE&gt;032021: Feb  1 2021 20:37:59.481 UTC: %SEC_LOGIN-5-LOGIN_SUCCESS: Login Success [user: admin-biera] [Source: 172.31.25.26] [localport: 22] at 06:37:59 AEST Tue Feb 2 2021&lt;/PRE&gt;
&lt;P&gt;Do you get those two different messages from the same switch?&amp;nbsp; Perhaps it's from the console login (I can't test that - not on-site)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Feb 2021 20:43:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/difference-between-ssh-5-ss2-userauth-and-sec-login-5-login/m-p/4283906#M565166</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2021-02-01T20:43:44Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between %SSH-5-SS2_USERAUTH and %SEC_LOGIN-5-LOGIN_SUCCESS and %SSH-5-SS2_SESSION</title>
      <link>https://community.cisco.com/t5/network-access-control/difference-between-ssh-5-ss2-userauth-and-sec-login-5-login/m-p/4285817#M565262</link>
      <description>&lt;P&gt;From&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/support/ios-nx-os-software/ios-xe-16/products-system-message-guides-list.html" target="_self"&gt;Cisco IOS XE Gibraltar 16 Error and System Messages&lt;/A&gt;, download&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/dam/en/us/td/docs/switches/lan/sys_messages/16-12/smg_1612x.xlsx" target="_self"&gt;System Message Guide for Cisco Catalyst Series Switches, Cisco IOS XE Gibraltar 16.12.x (XLSX - 1 MB)&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE width="1997"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="371" style="font-weight: 400;"&gt;&amp;nbsp;SSH-5-SSH_SESSION&lt;/TD&gt;
&lt;TD width="115" style="font-weight: 400;"&gt;&amp;nbsp;5-Notice&lt;/TD&gt;
&lt;TD width="591" style="font-weight: 400;"&gt;&amp;nbsp; SSH Session request from [chars] tty = [dec] using crypto cipher '[chars]' [chars]&lt;/TD&gt;
&lt;TD width="423" style="font-weight: 400;"&gt;&amp;nbsp;The SSH session request information&lt;/TD&gt;
&lt;TD width="116" style="font-weight: 400;"&gt;&amp;nbsp;ssh&lt;/TD&gt;
&lt;TD width="381" style="font-weight: 400;"&gt;&amp;nbsp;"No action necessary - informational message"&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD style="font-weight: 400;"&gt;&amp;nbsp;SSH-5-SSH_USERAUTH&lt;/TD&gt;
&lt;TD style="font-weight: 400;"&gt;&amp;nbsp;5-Notice&lt;/TD&gt;
&lt;TD style="font-weight: 400;"&gt;&amp;nbsp; User '[chars]' authentication for SSH Session from [chars] tty = [dec]&amp;nbsp;&lt;/TD&gt;
&lt;TD style="font-weight: 400;"&gt;&amp;nbsp;The SSH user authentication status information&lt;/TD&gt;
&lt;TD style="font-weight: 400;"&gt;&amp;nbsp;ssh&lt;/TD&gt;
&lt;TD style="font-weight: 400;"&gt;&amp;nbsp;"No action necessary - informational message"&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;TABLE width="1997"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="371" style="font-weight: 400;"&gt;&amp;nbsp;SEC_LOGIN-5-LOGIN_SUCCESS&lt;/TD&gt;
&lt;TD width="115" style="font-weight: 400;"&gt;&amp;nbsp;5-Notice&lt;/TD&gt;
&lt;TD width="591" style="font-weight: 400;"&gt;&amp;nbsp; Login Success [user: [chars]] [Source: [chars]] [localport: [dec]] at [chars]&lt;/TD&gt;
&lt;TD width="423" style="font-weight: 400;"&gt;&amp;nbsp;A successful login happened with the device.&lt;/TD&gt;
&lt;TD width="116" style="font-weight: 400;"&gt;&amp;nbsp;os&lt;/TD&gt;
&lt;TD width="381" style="font-weight: 400;"&gt;&amp;nbsp;"A notification that login succeeded."&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After following&amp;nbsp;&lt;A href="https://community.cisco.com/t5/switching/ssh-and-telnet-logs/m-p/3179156/highlight/true#M390381" target="_self"&gt;Julio E. Moisa suggested "ip ssh logging event"&lt;/A&gt;,&amp;nbsp; got on a C9300 running IOS-XE&amp;nbsp;17.03.02a&lt;/P&gt;
&lt;PRE&gt;Feb  4 06:09:58.515: %SSH-5-SSH2_SESSION: SSH2 Session request from 10.1.100.110 (tty = 3) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256' Succeeded
Feb  4 06:09:58.547: %SEC_LOGIN-5-LOGIN_SUCCESS: Login Success [user: cisco] [Source: 10.1.100.110] [localport: 22] at 06:09:58 UTC Thu Feb 4 2021
Feb  4 06:09:58.547: %SSH-5-SSH2_USERAUTH: User 'cisco' authentication for SSH2 Session from 10.1.100.110 (tty = 3) using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256' Succeeded
Feb  4 06:09:59.069: %SSH-5-SSH2_CLOSE: SSH2 Session from 10.1.100.110 (tty = 1) for user '' using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256' closed
Feb  4 06:10:00.664: %SSH-5-SSH2_CLOSE: SSH2 Session from 10.1.100.110 (tty = 3) for user '' using crypto cipher 'aes128-ctr', hmac 'hmac-sha2-256' closed
&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Feb 2021 06:13:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/difference-between-ssh-5-ss2-userauth-and-sec-login-5-login/m-p/4285817#M565262</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2021-02-04T06:13:07Z</dc:date>
    </item>
  </channel>
</rss>

