<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic follow-up questions: in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/tracking-remote-logon-access-to-my-3750-switch/m-p/2807144#M915627</link>
    <description>&lt;P&gt;follow-up questions:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;1. Does AAA require a central server with specific software? And by server, does it mean a computer?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2. These lines are at the end of the config:&lt;/P&gt;
&lt;P&gt;line con 0&lt;BR /&gt; password x&lt;BR /&gt; login&lt;BR /&gt; exec-timeout 2 30&lt;BR /&gt;line vty 0 4&lt;BR /&gt; password x&lt;BR /&gt; login&lt;BR /&gt; exec-timeout 2 30&lt;BR /&gt;line vty 5 15&lt;BR /&gt; password x&lt;/P&gt;
&lt;P&gt;login&lt;BR /&gt; exec-timeout 2 30&lt;/P&gt;
&lt;P&gt;Wouldn't "line 0 15" do the same thing if the passwords are the same?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3. What about system messages saved to the default syslog? Are these cleared once you log out of console or vty?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 18 Dec 2015 18:09:33 GMT</pubDate>
    <dc:creator>doddman11</dc:creator>
    <dc:date>2015-12-18T18:09:33Z</dc:date>
    <item>
      <title>Tracking remote logon access to my 3750 switch</title>
      <link>https://community.cisco.com/t5/network-security/tracking-remote-logon-access-to-my-3750-switch/m-p/2807139#M915618</link>
      <description>&lt;P&gt;I need to know if someone logged into my switch without my knowledge. Is this information in default logs?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 13:39:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tracking-remote-logon-access-to-my-3750-switch/m-p/2807139#M915618</guid>
      <dc:creator>doddman11</dc:creator>
      <dc:date>2020-02-21T13:39:00Z</dc:date>
    </item>
    <item>
      <title>Do you have some TACACS or</title>
      <link>https://community.cisco.com/t5/network-security/tracking-remote-logon-access-to-my-3750-switch/m-p/2807140#M915619</link>
      <description>&lt;P&gt;Do you have some TACACS or similar configured?&lt;/P&gt;</description>
      <pubDate>Fri, 18 Dec 2015 16:43:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tracking-remote-logon-access-to-my-3750-switch/m-p/2807140#M915619</guid>
      <dc:creator>7367wells</dc:creator>
      <dc:date>2015-12-18T16:43:33Z</dc:date>
    </item>
    <item>
      <title>I had to google this term - I</title>
      <link>https://community.cisco.com/t5/network-security/tracking-remote-logon-access-to-my-3750-switch/m-p/2807141#M915622</link>
      <description>&lt;P&gt;I had to google this term - I do not.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Dec 2015 16:56:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tracking-remote-logon-access-to-my-3750-switch/m-p/2807141#M915622</guid>
      <dc:creator>doddman11</dc:creator>
      <dc:date>2015-12-18T16:56:47Z</dc:date>
    </item>
    <item>
      <title>Ah okay, in that case I dont</title>
      <link>https://community.cisco.com/t5/network-security/tracking-remote-logon-access-to-my-3750-switch/m-p/2807142#M915624</link>
      <description>&lt;P&gt;Ah okay, in that case I dont know of a way to do it.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;In the short term you can set up an ACL to restrict which VLANs have access via SSH to your switch. Then research setting up some kind AAA method, that way you can make sure there is a log of who is authenticating, a list of who can authenticate and what commands they have done.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Dec 2015 17:05:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tracking-remote-logon-access-to-my-3750-switch/m-p/2807142#M915624</guid>
      <dc:creator>7367wells</dc:creator>
      <dc:date>2015-12-18T17:05:32Z</dc:date>
    </item>
    <item>
      <title>Thanks for your help and time</title>
      <link>https://community.cisco.com/t5/network-security/tracking-remote-logon-access-to-my-3750-switch/m-p/2807143#M915626</link>
      <description>&lt;P&gt;Thanks for your help and time.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Dec 2015 17:39:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tracking-remote-logon-access-to-my-3750-switch/m-p/2807143#M915626</guid>
      <dc:creator>doddman11</dc:creator>
      <dc:date>2015-12-18T17:39:45Z</dc:date>
    </item>
    <item>
      <title>follow-up questions:</title>
      <link>https://community.cisco.com/t5/network-security/tracking-remote-logon-access-to-my-3750-switch/m-p/2807144#M915627</link>
      <description>&lt;P&gt;follow-up questions:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;1. Does AAA require a central server with specific software? And by server, does it mean a computer?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2. These lines are at the end of the config:&lt;/P&gt;
&lt;P&gt;line con 0&lt;BR /&gt; password x&lt;BR /&gt; login&lt;BR /&gt; exec-timeout 2 30&lt;BR /&gt;line vty 0 4&lt;BR /&gt; password x&lt;BR /&gt; login&lt;BR /&gt; exec-timeout 2 30&lt;BR /&gt;line vty 5 15&lt;BR /&gt; password x&lt;/P&gt;
&lt;P&gt;login&lt;BR /&gt; exec-timeout 2 30&lt;/P&gt;
&lt;P&gt;Wouldn't "line 0 15" do the same thing if the passwords are the same?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3. What about system messages saved to the default syslog? Are these cleared once you log out of console or vty?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Dec 2015 18:09:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tracking-remote-logon-access-to-my-3750-switch/m-p/2807144#M915627</guid>
      <dc:creator>doddman11</dc:creator>
      <dc:date>2015-12-18T18:09:33Z</dc:date>
    </item>
    <item>
      <title>1. Yes you configure ACS on a</title>
      <link>https://community.cisco.com/t5/network-security/tracking-remote-logon-access-to-my-3750-switch/m-p/2807145#M915629</link>
      <description>&lt;P&gt;1. Yes you configure ACS on a server (virtual is fine). Then you can configure the switch to authenticate that ACS server. (ACS provides the AAA)&lt;/P&gt;
&lt;P&gt;2.&amp;nbsp;https://learningnetwork.cisco.com/thread/2367 &amp;nbsp;should be able to shed some light on that for you. Incidentally you have exec timeout configured on only the first 5 lines.&lt;/P&gt;
&lt;P&gt;3. I think you are referring to the normal log (show log) then it isnt cleared when you log out.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Dec 2015 15:10:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tracking-remote-logon-access-to-my-3750-switch/m-p/2807145#M915629</guid>
      <dc:creator>7367wells</dc:creator>
      <dc:date>2015-12-21T15:10:32Z</dc:date>
    </item>
  </channel>
</rss>

