<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Auditing the admin guy in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/auditing-the-admin-guy/m-p/2267748#M350162</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is the difference to what I am doing and what is stopping me from turning accounting off and making a malicious change then turning it back on so I dont get noticed?&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 09 May 2013 17:58:31 GMT</pubDate>
    <dc:creator>Andy White</dc:creator>
    <dc:date>2013-05-09T17:58:31Z</dc:date>
    <item>
      <title>Auditing the admin guy</title>
      <link>https://community.cisco.com/t5/network-security/auditing-the-admin-guy/m-p/2267746#M350159</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I log everything from my ASAs to a syslog server, so when I make any changes there is an audit trail of what I have been doing, however my boss said what is stopping you turning off the logging and doing something malicious and then turning the logging back on?&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Firstly if I turn off or on logging can it send a syslog message?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Secondly is there any software out there that can help?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 01:41:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/auditing-the-admin-guy/m-p/2267746#M350159</guid>
      <dc:creator>Andy White</dc:creator>
      <dc:date>2019-03-12T01:41:11Z</dc:date>
    </item>
    <item>
      <title>Auditing the admin guy</title>
      <link>https://community.cisco.com/t5/network-security/auditing-the-admin-guy/m-p/2267747#M350161</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Andy,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Why dont you use AAA accounting and you can audit all of the commands you enter while being logged into the ASA, you can then export them to a syslog server to analize them,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That would be a great way to do it, don't you think?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio Carvajal &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 May 2013 16:53:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/auditing-the-admin-guy/m-p/2267747#M350161</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-05-09T16:53:00Z</dc:date>
    </item>
    <item>
      <title>Auditing the admin guy</title>
      <link>https://community.cisco.com/t5/network-security/auditing-the-admin-guy/m-p/2267748#M350162</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is the difference to what I am doing and what is stopping me from turning accounting off and making a malicious change then turning it back on so I dont get noticed?&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 May 2013 17:58:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/auditing-the-admin-guy/m-p/2267748#M350162</guid>
      <dc:creator>Andy White</dc:creator>
      <dc:date>2013-05-09T17:58:31Z</dc:date>
    </item>
    <item>
      <title>Re: Auditing the admin guy</title>
      <link>https://community.cisco.com/t5/network-security/auditing-the-admin-guy/m-p/2267749#M350163</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;for me, it looks like what would stop an admin from turning off logging/accounting is leveraging those two commands to some higher privilege level (command authorization) which only the boss can have. say level 14 can execute all commands except disabling logging (or aaa accounting), and disabling aaa command authorization,&amp;nbsp; which will&amp;nbsp; be available only for level 15. &lt;/P&gt;&lt;P&gt;An admin should have level 14, and a boss should have level 15.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the question now turns into: "what is stopping a boss turning off the logging and doing something malicious ?", then i believe it would be an issue of trust and ethics.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps &lt;/P&gt;&lt;P&gt;------------------ &lt;BR /&gt;Mashal Alshboul&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 May 2013 18:57:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/auditing-the-admin-guy/m-p/2267749#M350163</guid>
      <dc:creator>malshbou</dc:creator>
      <dc:date>2013-05-09T18:57:27Z</dc:date>
    </item>
    <item>
      <title>Re: Auditing the admin guy</title>
      <link>https://community.cisco.com/t5/network-security/auditing-the-admin-guy/m-p/2267750#M350164</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Andy,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I set aaa accounting it mean that you were going to run authentication and then you could use the AAA framework for the extra-work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Setting a shell profile policy stating that you are allow to set any command except&amp;nbsp; the ones that stop the logging stuff and the aaa accounting stop,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I mean you have it all within the AAA framework........&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 May 2013 19:09:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/auditing-the-admin-guy/m-p/2267750#M350164</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-05-09T19:09:05Z</dc:date>
    </item>
    <item>
      <title>Re: Auditing the admin guy</title>
      <link>https://community.cisco.com/t5/network-security/auditing-the-admin-guy/m-p/2267751#M350165</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I agree with Mashal, this can be achieved using command authorization. You may use LOCAL or tacacs+.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 11 May 2013 21:03:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/auditing-the-admin-guy/m-p/2267751#M350165</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-05-11T21:03:02Z</dc:date>
    </item>
  </channel>
</rss>

