Support for Logging IKE and PKI Transaction Details

FastIron devices support logging of IKE and PKI transaction details. The log files are automatically generated syslog messages that contain the transaction details.

There are two types or levels of logging. Standard logging is enabled by default. The second type of logging is called extended logging, which you must enable using commands. This type of logging allows you to log additional IKE or PKI transaction details.

The following additional logging options can be configured in general configuration mode:

  • logging enable ikev2
  • logging enable ikev2 ikev2-extended
  • logging enable ikev2 ikev2-packet
  • logging enable pki
  • logging enable pki pki-extended

For example, enter the following commands to configure extended logging for PKI and IKEv2:

Device# configure terminal
Device(config)# logging enable ikev2-extended
Device(config)# logging enable pki-extended

Once the extended logging commands are configured for IKE and PKI, the logs listed in the following table are generated on the ICX device.

Extended Logging Messages

Event Audit Log
Certificate time (validity period) expired. Certificate has expired.
Signature is not valid. Certificate signature failure.
Extended Key Usage support does not have expected key purposes. Unsupported certificate purpose.
Certificate is revoked by CA (applies to both chain and non-chained case). Revoked.
Wrong root certificate received in a certificate chain. Unable to get local issuer certificate.
Configured DN value does not match with peer certificate remote DN. Hostname mismatch.
OCSP Response does not have OCSPSigning bit set. OCSP purpose missing in responder certificate.
There is a fingerprint mismatch. Fingerprint match failed.

Required hardware

The hardware requirements are identical for default logging and extended logging. The following table lists the required hardware.

Required hardware for IPsec

Device Module

FastIron ICX 7450

ICX7400-SERVICE-MOD Module

Note: The FastIron device should have at least one interface module through which the external syslog server can be reached.

Limitations

All of the current limitations of the logging feature on FastIron devices and the limitations of the IPsec security feature apply to the logging of IKE and PKI transaction details.

In addition, there are some limitations specific to the feature for logging IKE and PKI transaction details. The following table lists the current limitations for this feature.

IKE and PKI logging limitations

Default and Extended Logging Description
IKE transaction details (send and receive packets) An IKEv2 packet that together with protocol headers totals more than 250 bytes will be logged in multiple syslog messages.