03-10-2017 10:26 AM - edited 03-08-2019 09:41 AM
We have cisco router and after checking the log I saw this message:
pam_aaa:authentication failed from <ipaddress> -sshd[2909]
pam_aaa:authentication failed from <ipaddress> -sshd[2913]
pam_aaa:authentication failed from <ipaddress> -sshd[3158]
I wanted to validate that number inside the [] brackets are the source port number? Any reference or direction to a Cisco documentation of the message is much appreciated.
Alex
03-10-2017 11:33 AM
This document references to Nexus but you may be able to use it for your router to troubleshoot the issue.
The local user database does not contain the user account that the user is using to login with.
Perform the following steps to check the authentication fallback method.
03-10-2017 12:04 PM
Hi Reza, I'm really more interested on the the numeric characters inside the [] bracket. I looked in this doc http://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_usr_aaa/configuration/15-sy/sec-usr-aaa-15-sy-book/sec-message-banners.html
It was not clear enough to say that the numerical character in the bracket [] are the port number.
pam_aaa:authentication failed from <ipaddress> -sshd[2909]
I'm not looking for the reason for the error message; but more to the substance of the number inside the bracket []. Is it the source port # of the device who failed to login or something else that Cisco have defined?
BTW, the device is a Cisco MDS 9396S and I'm checking the link you've provided as well and see if there's any info that fit to what I'm looking for.
03-11-2017 01:47 PM
Hi Alex,
You are right. The document is not clear but you can actually test it for your self.
You can simply open an SSH session to the Cisco device and than use "sh tcp brief all" command to see the source and destination port for the ssh session and match it with what is in the logs.
The output of "sh tcp brief all" should look like this. The source port is 56044
TCB Local Address Foreign Address (state)
3D9B0DDC 10.10.80.75.22 10.10.152.81.56044 ESTAB
HTH
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide