Support for Logging IKE and PKI Transaction Details
There are two types or levels of logging. Standard logging is enabled by default. The second type of logging is called extended logging, which you must enable using commands. This type of logging allows you to log additional IKE or PKI transaction details.
The following additional logging options can be configured in general configuration mode:
logging enable ikev2logging enable ikev2 ikev2-extendedlogging enable ikev2 ikev2-packetlogging enable pkilogging enable pki pki-extended
For example, enter the following commands to configure extended logging for PKI and IKEv2:
Device# configure terminal Device(config)# logging enable ikev2-extended Device(config)# logging enable pki-extended
Once the extended logging commands are configured for IKE and PKI, the logs listed in the following table are generated on the ICX device.
Extended Logging Messages
| Event | Audit Log |
|---|---|
| Certificate time (validity period) expired. | Certificate has expired. |
| Signature is not valid. | Certificate signature failure. |
| Extended Key Usage support does not have expected key purposes. | Unsupported certificate purpose. |
| Certificate is revoked by CA (applies to both chain and non-chained case). | Revoked. |
| Wrong root certificate received in a certificate chain. | Unable to get local issuer certificate. |
| Configured DN value does not match with peer certificate remote DN. | Hostname mismatch. |
| OCSP Response does not have OCSPSigning bit set. | OCSP purpose missing in responder certificate. |
| There is a fingerprint mismatch. | Fingerprint match failed. |
Required hardware
The hardware requirements are identical for default logging and extended logging. The following table lists the required hardware.
Limitations
All of the current limitations of the logging feature on FastIron devices and the limitations of the IPsec security feature apply to the logging of IKE and PKI transaction details.
In addition, there are some limitations specific to the feature for logging IKE and PKI transaction details. The following table lists the current limitations for this feature.