04-05-2005 04:27 AM
Hi,
I've got a pair of 3845s running 12.3(14)T. When they reload, the following appears in the log:
R3845-1#sh logg | i PARSER
000022: *Apr 5 13:15:31.515 BST: %PARSER-5-CFGLOG_LOGGEDCMD: User:console logged command:access-list 199 permit icmp host 10.10.10.10 host 20.20.20.20
000023: *Apr 5 13:15:31.515 BST: %PARSER-5-CFGLOG_LOGGEDCMD: User:console logged command:crypto map NiStTeSt1 10 ipsec-manual
000024: *Apr 5 13:15:31.515 BST: %PARSER-5-CFGLOG_LOGGEDCMD: User:console logged command:match address 199
000025: *Apr 5 13:15:31.515 BST: %PARSER-5-CFGLOG_LOGGEDCMD: User:console logged command:set peer 20.20.20.20
000026: *Apr 5 13:15:31.519 BST: %PARSER-5-CFGLOG_LOGGEDCMD: User:console logged command:exit
000030: *Apr 5 13:15:31.887 BST: %PARSER-5-CFGLOG_LOGGEDCMD: User:console logged command:no access-list 199
000031: *Apr 5 13:15:31.891 BST: %PARSER-5-CFGLOG_LOGGEDCMD: User:console logged command:no crypto map NiStTeSt1
Needless to say, none of this is in my startup config, and I've never entered any of those commands in my life.
What's going on?
thanks,
alec
04-05-2005 05:43 AM
Alec
I have noticed that SDM does some things including creating an access list that appears when I do show access-list but does not show up in show run. I wonder if what you are seeing is also something done by SDM. Or perhaps it is remnants of some testing done in the code and only partially removed. My guess is that it is not doing anything that will impact your operation.
HTH
Rick
04-05-2005 05:54 AM
Hi Rick,
Thanks for the reply.
All of this happens really early on in the boot process, even before interfaces come up. I'd probably agree with you when you say this is partially-removed testing code.
However, there are a couple of interesting points:
- IOS has carte blanche to change your running config without your consent and without you noticing.
- ...unless you're using the "log config" commands...
I'm reasonably certain that nothing untowards is going on; I'm just surprised to see what appears to be a covert IPSec channel being partially built and then torn down :)
thanks,
alec
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide