12-18-2023 01:41 PM
We have two FTD 1140Ns in an HA environment managed by a FMCv. Both are running 7.2.5. I setup a flexconfig statement to do
"aaa local authentication attempts max-fail 5"
We have seen the command work during a production day. We then run "clear aaa local user lockout username username" to clear it.
Weird thing is I can see in the syslog the user attempting to put in their password incorrectly (syslog id 113015). I do not see the user get locked out (syslog id 113006) or the unlock we do (syslog id 113007).
Like I mentioned the unlock works. I was trying to setup a syslog event based alert to let us know about the lockout itself and I was hoping to base it off syslog id 113006.
Any ideas?
12-19-2023 12:05 AM
can you try increase the logging queue
then check again
MHM
12-19-2023 04:46 AM
MHM,
Would that be under platform settings, syslog, logging setup?
12-19-2023 05:36 AM
It already high
In syslog servers tab' increase the message queue also and check result.
MHM
12-22-2023 02:55 AM
Since you ship logs to a syslog/siem i would personally use a lower value as these local logs should be used only in very specific circumstances.
12-22-2023 04:22 AM - edited 12-22-2023 04:23 AM
So you do not see the user locked event generated, do you see use locked after the attempts done ?
syslog settings - check by any chance that event Id disabled ?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide