<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Firewall context not generating user information while logging in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firewall-context-not-generating-user-information-while-logging/m-p/2176337#M359992</link>
    <description>&lt;P&gt;Dear Experts,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am facing an issue for syslog messages that is not&amp;nbsp; getting logged with user login information. Firewall is configured in&amp;nbsp; multi-context mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Admin context is configured with syslog configuration&amp;nbsp; and i am getting the local syslog messages about the user login&amp;nbsp; information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did the same syslog server configuration for other contexts , but the local syslog message doesnt have the user information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you kindly advice whether any limitation exists for multicontext firewall logging ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind advice.&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 01:15:24 GMT</pubDate>
    <dc:creator>s.aliyarukunju</dc:creator>
    <dc:date>2019-03-12T01:15:24Z</dc:date>
    <item>
      <title>Firewall context not generating user information while logging</title>
      <link>https://community.cisco.com/t5/network-security/firewall-context-not-generating-user-information-while-logging/m-p/2176337#M359992</link>
      <description>&lt;P&gt;Dear Experts,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am facing an issue for syslog messages that is not&amp;nbsp; getting logged with user login information. Firewall is configured in&amp;nbsp; multi-context mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Admin context is configured with syslog configuration&amp;nbsp; and i am getting the local syslog messages about the user login&amp;nbsp; information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did the same syslog server configuration for other contexts , but the local syslog message doesnt have the user information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you kindly advice whether any limitation exists for multicontext firewall logging ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind advice.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 01:15:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-context-not-generating-user-information-while-logging/m-p/2176337#M359992</guid>
      <dc:creator>s.aliyarukunju</dc:creator>
      <dc:date>2019-03-12T01:15:24Z</dc:date>
    </item>
    <item>
      <title>Firewall context not generating user information while logging</title>
      <link>https://community.cisco.com/t5/network-security/firewall-context-not-generating-user-information-while-logging/m-p/2176338#M359993</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Does this happen when you access the context directly or when you are coming from the "system" context?&lt;/P&gt;&lt;P&gt;What is the log ID that you are refering to?&lt;/P&gt;&lt;P&gt;Can you provide a sample of both logs? With and without the user information. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Mar 2013 20:06:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-context-not-generating-user-information-while-logging/m-p/2176338#M359993</guid>
      <dc:creator>jocamare</dc:creator>
      <dc:date>2013-03-18T20:06:47Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall context not generating user information while loggi</title>
      <link>https://community.cisco.com/t5/network-security/firewall-context-not-generating-user-information-while-logging/m-p/2176339#M359995</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jocamare,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me clarfiy you more about this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have two context now , Admin and one customer context. Each context is having the dedicated management interface vlan.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When i am trying to access Admin context directly&amp;nbsp; through managment interface , it will show the local syslog message with&amp;nbsp; login user information.But when i am trying the same for customer&amp;nbsp; context through the management interface , syslog message is not showing&amp;nbsp; the login user information , eventhough the syslog configuration is&amp;nbsp; same on both the context.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The log ID that i am refering is &lt;STRONG&gt;%FWSM-6-605005 . Below is the sample log files that generated on admin context while login.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mar 19 2013 09:37:00: %FWSM-6-605005: Login permitted from 10.10.2.10/62219 to management:192.168.&lt;/P&gt;&lt;P&gt;1.4/telnet for user "abc"&lt;/P&gt;&lt;P&gt;Mar 19 2013 09:37:10: %FWSM-5-502103: User priv level changed: Uname: abc From: 1 To: 15&lt;/P&gt;&lt;P&gt;Mar 19 2013 09:37:10: %FWSM-5-111008: User 'abc' executed the 'enable' command.&lt;/P&gt;&lt;P&gt;Mar 19 2013 09:37:12: %FWSM-7-111009: User 'abc' executed cmd: show running-config username&lt;/P&gt;&lt;P&gt;Mar 19 2013 09:37:22: %FWSM-7-111009: User 'abc' executed cmd: show running-config logging&lt;/P&gt;&lt;P&gt;Mar 19 2013 09:37:27: %FWSM-7-111009: User 'abc' executed cmd: show logging&lt;/P&gt;&lt;P&gt;Mar 19 2013 09:38:05: %FWSM-7-111009: User 'abc' executed cmd: show logging&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Syslog configuration is Admin Context is shown below&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;logging enable&lt;/P&gt;&lt;P&gt;logging timestamp&lt;/P&gt;&lt;P&gt;logging buffer-size 104857&lt;/P&gt;&lt;P&gt;logging console informational&lt;/P&gt;&lt;P&gt;logging buffered debugging&lt;/P&gt;&lt;P&gt;logging trap notifications&lt;/P&gt;&lt;P&gt;logging facility 16&lt;/P&gt;&lt;P&gt;logging host management X.X.X.X&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Syslog configuration is Customer Context is shown below&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;logging enable&lt;/P&gt;&lt;P&gt;logging timestamp&lt;/P&gt;&lt;P&gt;logging buffer-size 104857&lt;/P&gt;&lt;P&gt;logging console informational&lt;/P&gt;&lt;P&gt;logging monitor notifications&lt;/P&gt;&lt;P&gt;logging buffered debugging&lt;/P&gt;&lt;P&gt;logging trap notifications&lt;/P&gt;&lt;P&gt;logging asdm informational&lt;/P&gt;&lt;P&gt;logging facility 16&lt;/P&gt;&lt;P&gt;logging host management X.X.X.X&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note :- I am not able to get the any user log messages from customer context to paste it here.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Mar 2013 07:01:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-context-not-generating-user-information-while-logging/m-p/2176339#M359995</guid>
      <dc:creator>s.aliyarukunju</dc:creator>
      <dc:date>2013-03-19T07:01:18Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall context not generating user information while loggi</title>
      <link>https://community.cisco.com/t5/network-security/firewall-context-not-generating-user-information-while-logging/m-p/2176340#M359997</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just tested this on my lab. 9.1(1)&lt;/P&gt;&lt;P&gt;It works for me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Seems to me the reason why you are not seeing the information you need is because the telnet connections are not authenticating against any database. They just get in using the default telnet password.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What does the output of the "&lt;STRONG&gt;show run aaa&lt;/STRONG&gt;" command from the client context show?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Mar 2013 02:46:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-context-not-generating-user-information-while-logging/m-p/2176340#M359997</guid>
      <dc:creator>jocamare</dc:creator>
      <dc:date>2013-03-20T02:46:32Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall context not generating user information while loggi</title>
      <link>https://community.cisco.com/t5/network-security/firewall-context-not-generating-user-information-while-logging/m-p/2176341#M359999</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thats good news...Below are the aaa commands from cleint context &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From Cleint conext ( without AAA server)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;aaa authentication http console LOCAL&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;aaa authentication ssh console LOCAL&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;aaa authentication enable console LOCAL&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now i added the below aaa commands and i am able to&amp;nbsp; get the user login info while telneting.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;aaa authentication telnet console LOCAL&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you please advice whether i missed any config commands&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Mar 2013 06:31:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-context-not-generating-user-information-while-logging/m-p/2176341#M359999</guid>
      <dc:creator>s.aliyarukunju</dc:creator>
      <dc:date>2013-03-20T06:31:40Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall context not generating user information while loggi</title>
      <link>https://community.cisco.com/t5/network-security/firewall-context-not-generating-user-information-while-logging/m-p/2176342#M360001</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Not sure i understand the request, but yeah, you missed the "aaa authentication..." command.&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Mar 2013 07:18:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-context-not-generating-user-information-while-logging/m-p/2176342#M360001</guid>
      <dc:creator>jocamare</dc:creator>
      <dc:date>2013-03-20T07:18:27Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall context not generating user information while loggi</title>
      <link>https://community.cisco.com/t5/network-security/firewall-context-not-generating-user-information-while-logging/m-p/2176343#M360003</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your advice jocamare.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now the issue of getting local syslog message with login user information is solved. But on syslog server i am not getting the severity informational messages.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Below are the syslog message in Local Buffer of firewall &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Mar 20 2013 15:14:44: %FWSM-6-605005: Login permitted from 10.10.10.2/59698 to management:20.20.20.2/telnet for user "abc"&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Mar 20 2013 15:18:43: %FWSM-5-502103: User priv level changed: Uname: abc From: 1 To: 15&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Mar 20 2013 15:18:43: %FWSM-5-111008: User 'abc' executed the 'enable' command.&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Below are the syslog message in syslog server logs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;Mar 20 15:18:00 20.20.20.2 Mar 20 2013 15:18:43: %FWSM-5-502103: User priv level changed: Uname: abc From: 1 To: 15 &lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;Mar 20 15:18:00 20.20.20.2 Mar 20 2013 15:18:43: %FWSM-5-111008: User 'abc' executed the 'enable' command. &lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you please advice , how can i get the message ID &lt;STRONG&gt;&lt;EM&gt;FWSM-6-605005 &lt;/EM&gt;&lt;/STRONG&gt;on syslog server ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Mar 2013 09:20:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-context-not-generating-user-information-while-logging/m-p/2176343#M360003</guid>
      <dc:creator>s.aliyarukunju</dc:creator>
      <dc:date>2013-03-21T09:20:18Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall context not generating user information while loggi</title>
      <link>https://community.cisco.com/t5/network-security/firewall-context-not-generating-user-information-while-logging/m-p/2176344#M360004</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;logging trap informational&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Mar 2013 19:02:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-context-not-generating-user-information-while-logging/m-p/2176344#M360004</guid>
      <dc:creator>jocamare</dc:creator>
      <dc:date>2013-03-22T19:02:15Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall context not generating user information while loggi</title>
      <link>https://community.cisco.com/t5/network-security/firewall-context-not-generating-user-information-while-logging/m-p/2176345#M360005</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Many thanks Jocamare...Its works fine now.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Mar 2013 09:38:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-context-not-generating-user-information-while-logging/m-p/2176345#M360005</guid>
      <dc:creator>s.aliyarukunju</dc:creator>
      <dc:date>2013-03-26T09:38:00Z</dc:date>
    </item>
  </channel>
</rss>

