<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Enable_1 user on FTD in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/enable-1-user-on-ftd/m-p/4714918#M1094722</link>
    <description>&lt;P&gt;Enable_1 ...Enable_15 are the default admin users on the FTD. Not sure why it behaves like that but that has always been the case even when I logged in with local username( not the default admin).&lt;/P&gt;&lt;P&gt;&lt;A href="https://quickview.cloudapps.cisco.com/quickview/bug/CSCvi23216" target="_blank"&gt;https://quickview.cloudapps.cisco.com/quickview/bug/CSCvi23216&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 02 Nov 2022 15:10:28 GMT</pubDate>
    <dc:creator>buffkata</dc:creator>
    <dc:date>2022-11-02T15:10:28Z</dc:date>
    <item>
      <title>Enable_1 user on FTD</title>
      <link>https://community.cisco.com/t5/network-security/enable-1-user-on-ftd/m-p/4714876#M1094717</link>
      <description>&lt;P&gt;Dears,&lt;/P&gt;&lt;P&gt;I found the following log amongst the email received from our FTD:&lt;/P&gt;&lt;P&gt;&amp;lt;173&amp;gt;:Nov 02 2022 12:44:28: %FTD-config-5-111010: User 'enable_1', running 'N/A' from IP 0.0.0.0, executed 'copy /noconfirm system:running-config disk0:/running-config-backup.txt'&lt;/P&gt;&lt;P&gt;And as at this time on the timestamp i didn't make any change on the firewall or run a backup on the firewall.&lt;/P&gt;&lt;P&gt;Please what does this command mean and also the enable_1 is it the default admin user on the FTD device or another user&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2022 14:10:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/enable-1-user-on-ftd/m-p/4714876#M1094717</guid>
      <dc:creator>systems100</dc:creator>
      <dc:date>2022-11-02T14:10:41Z</dc:date>
    </item>
    <item>
      <title>Re: Enable_1 user on FTD</title>
      <link>https://community.cisco.com/t5/network-security/enable-1-user-on-ftd/m-p/4714889#M1094720</link>
      <description>&lt;P&gt;%FTD-config-5-111010&amp;nbsp;&amp;nbsp; - check more logs, the command trying to copy config backup.&lt;/P&gt;
&lt;H3 id="ariaid-title125" class="title topictitle3"&gt;111010&lt;/H3&gt;
&lt;SECTION class="body conbody"&gt;
&lt;P class="p"&gt;&lt;STRONG class="ph b"&gt;Error Message&lt;/STRONG&gt; &lt;CODE class="ph codeph"&gt; %&lt;SPAN class="ph"&gt;FTD&lt;/SPAN&gt;-5-111010: User &lt;EM class="ph i"&gt;username&lt;/EM&gt; , running &lt;EM class="ph i"&gt;application-name&lt;/EM&gt; from IP &lt;EM class="ph i"&gt;ip addr&lt;/EM&gt; , executed &lt;EM class="ph i"&gt;cmd&lt;/EM&gt;
                                 			&lt;/CODE&gt;&lt;/P&gt;
&lt;P class="p"&gt;&lt;STRONG class="ph b"&gt;Explanation&lt;/STRONG&gt; A user made a configuration change.&lt;/P&gt;
&lt;UL id="con_8586950__ul_CB4F0DD3E5894D9584630ACDD434A5B2" class="ul"&gt;
&lt;LI id="con_8586950__li_2FEDCC8C76964F4BB790DFEEBC909A9C" class="li"&gt;&lt;EM class="ph i"&gt;username&lt;/EM&gt; —The user making the configuration change&lt;/LI&gt;
&lt;LI class="li"&gt;&lt;EM class="ph i"&gt;application-name&lt;/EM&gt; —The application that the user is running&lt;/LI&gt;
&lt;LI class="li"&gt;&lt;EM class="ph i"&gt;ip addr&lt;/EM&gt; —The IP address of the management station&lt;/LI&gt;
&lt;LI class="li"&gt;&lt;EM class="ph i"&gt;cmd&lt;/EM&gt; —The command that the user has executed&lt;/LI&gt;
&lt;/UL&gt;
&lt;/SECTION&gt;</description>
      <pubDate>Wed, 02 Nov 2022 14:25:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/enable-1-user-on-ftd/m-p/4714889#M1094720</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2022-11-02T14:25:21Z</dc:date>
    </item>
    <item>
      <title>Re: Enable_1 user on FTD</title>
      <link>https://community.cisco.com/t5/network-security/enable-1-user-on-ftd/m-p/4714918#M1094722</link>
      <description>&lt;P&gt;Enable_1 ...Enable_15 are the default admin users on the FTD. Not sure why it behaves like that but that has always been the case even when I logged in with local username( not the default admin).&lt;/P&gt;&lt;P&gt;&lt;A href="https://quickview.cloudapps.cisco.com/quickview/bug/CSCvi23216" target="_blank"&gt;https://quickview.cloudapps.cisco.com/quickview/bug/CSCvi23216&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2022 15:10:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/enable-1-user-on-ftd/m-p/4714918#M1094722</guid>
      <dc:creator>buffkata</dc:creator>
      <dc:date>2022-11-02T15:10:28Z</dc:date>
    </item>
    <item>
      <title>Re: Enable_1 user on FTD</title>
      <link>https://community.cisco.com/t5/network-security/enable-1-user-on-ftd/m-p/4714919#M1094723</link>
      <description>&lt;P&gt;There is no such user as enable_1 on the device.&lt;/P&gt;&lt;P&gt;So where could this be coming from.&lt;/P&gt;&lt;P&gt;Or could it be e that the device is running an ASA image alongside the FTD image and the is a unknown user running some configuration on the asa.&lt;/P&gt;&lt;P&gt;From my experience with FTD, it is not possible to issue such command as this&amp;nbsp;&lt;SPAN&gt;'copy /noconfirm system:running-config disk0:/running-config-backup.txt' on the FTD cli interface expect via expert mode.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;what do you think?.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2022 15:13:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/enable-1-user-on-ftd/m-p/4714919#M1094723</guid>
      <dc:creator>systems100</dc:creator>
      <dc:date>2022-11-02T15:13:19Z</dc:date>
    </item>
    <item>
      <title>Re: Enable_1 user on FTD</title>
      <link>https://community.cisco.com/t5/network-security/enable-1-user-on-ftd/m-p/4714935#M1094724</link>
      <description>&lt;P&gt;Do you mean when you login to the ftd as another user the log displays the user as Enable_1............Enable_15?&lt;/P&gt;&lt;P&gt;Also have come across such situation before where you find an activity carried out by a user you didn't create or does not exist on your firewall?.&lt;/P&gt;&lt;P&gt;Also am surprised that such command is showing on the ftd, since i know fully well the commands that demands global config privilege can not be carried out on the ftd clish or lian cli mode but all configs has to come via deployment from the FMC.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2022 15:43:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/enable-1-user-on-ftd/m-p/4714935#M1094724</guid>
      <dc:creator>systems100</dc:creator>
      <dc:date>2022-11-02T15:43:14Z</dc:date>
    </item>
    <item>
      <title>Re: Enable_1 user on FTD</title>
      <link>https://community.cisco.com/t5/network-security/enable-1-user-on-ftd/m-p/4715732#M1094750</link>
      <description>&lt;P&gt;Is there possibly a scheduled device backup task in your FMC? That would result in the log message you cited.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Nov 2022 15:57:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/enable-1-user-on-ftd/m-p/4715732#M1094750</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2022-11-03T15:57:18Z</dc:date>
    </item>
  </channel>
</rss>

