Syslog Messages in FIPS and CC Modes

The following table lists some of the syslog messages in FIPS and CC mode.

FIPS and CC Syslog Messages

Message Level

Message

Explanation

Alert

Time is updated by NTP server ip-address from NO_CLOCK to <new time> GMT+00 <new date>

Indicates time is updated by an NTP server.

Alert

Clock Changed from old time <old time> GMT+00 <old date> to new time <new time> GMT+00 <new date>

Indicates time is updated using the clock set command.

Informational

Interface ethernet mgmt1, state up

Indicates ICX device startup.

Informational

"ntp" by <username> from console

Indicates NTP is enabled by user

Informational

"no ntp" by <username> from console

Indicates NTP is disabled by user

Informational

"server <ip-address> key <key-id>" by <username> from console

Indicates NTP server is added by user

Informational

"no server <ip-address> key <key-id>" by <username>from console

Indicates NTP server is removed by user

Informational

FIPS: [primary/secondary] image verification success

The image copy and verification to primary or secondary flash are successful.

Informational

FIPS: [primary/secondary] image verification failed

Image verification in primary or secondary flash has failed.

Informational

SSH login by user from src IP ip-address, src MAC mac-address to USER EXEC mode using RSA as Server Host Key.

Indicates entry into the "user exec" mode for all sessions for the mentioned user. Similar message is logged for “privileged exec” mode.

Informational

PKI: Trustpoint - <truspoint_name>: Certificate validation failed - certificate has expired Cert ID - Serial No : <serial_number>, Issuer CN : <issuer_common_name>, Subject CN : <subject_common_name>

Certificate time (validity period) has expired.

Informational

PKI: Trustpoint - <truspoint_name>: OCSP - Certificate not valid, Reason : Revoked, code : -1 Cert ID - Serial No : <serial_number>, Issuer CN : <issuer_common_name>, Subject CN : <subject_common_name>

Certificate is revoked by CA (applies to both chain/non-chained case).

Informational

PKI: Trustpoint - <truspoint_name>: Certificate validation failed - certificate signature failure Cert ID - Serial No : <serial_number>, Issuer CN : <issuer_common_name>, Subject CN : <subject_common_name>

Signature is not valid.

Informational

PKI: Trustpoint - <truspoint_name> : OCSP - OCSP purpose missing in responder certificate Cert ID - Serial No : <serial_number>, Issuer CN : <issuer_common_name>, Subject CN : <subject_common_name>

OCSP Signing EKU missing in OCSP responder certificate.

Informational

PKI: Trustpoint - <truspoint_name> : Certificate Verification Successful. Cert ID - Serial No : <serial_number>, Issuer CN : <issuer_common_name>, Subject CN : <subject_common_name>

The server certificate has been validated successfully.

Informational

PKI: Trustpoint - <truspoint_name>: OCSP - Certificate not valid, Reason : Revoked, code : -1 Cert ID - Serial No : <serial_number>, Issuer CN : <issuer_common_name>, Subject CN : <subject_common_name>

Certificate time (validity period) has expired.

Informational

PKI: Trustpoint - <truspoint_name>: OCSP : Verify error:certificate is not yet valid Cert ID - Serial No : <serial_number>, Issuer CN : <issuer_common_name>, Subject CN : <subject_common_name>

Certificate time (validity period) is not yet valid.

Informational

PKI: Trustpoint - <truspoint_name>: Extended key usage validation failed - Unsupported certificate purpose Cert ID - Serial No : <serial_number>, Issuer CN : <issuer_common_name>, Subject CN : <subject_common_name>

Extended Key Usage support does not have expected key purposes.

Informational

PKI: Trustpoint - <truspoint_name>: Remote Domain name (example.com) validation failed with return code : 1 Cert ID - Serial No : <serial_number>, Issuer CN : <issuer_common_name>, Subject CN : <subject_common_name>

Remote domain name configured in SSL profile does not match with the domain name configured in certificate.

Informational

PKI: Trustpoint - <truspoint_name>: OCSP - Certificate is valid Cert ID - Serial No : <serial_number>, Issuer CN : <issuer_common_name>, Subject CN : <subject_common_name>

Certificate went through OCSP verification and is valid.

Informational

PKI: ocsp reply received from ocsp responder: <OCSPResponder> for trustpoint <trustpointname>.:revoke_status: failed error:OCSP purpose missing in responder certificate

OCSP Response doesn't have OCSPSigning bit set.

Informational

PKI: authenticate response received: trustpoint <trustpointName>. auth-status:failed. error:fingerprint match failed

There is a fingerprint mismatch between the retrieved fingerprint and configured fingerprint.

Informational

SSH logout by user from src IP ip-address, src MAC mac-address from USER EXEC mode using RSA as Server Host Key.

Indicates exit from "user exec" mode for all sessions for the mentioned user. Similar message is logged for “privileged exec” mode.

Informational

SSH timed out by admin from src IP ip-address from src MAC mac_address from USER EXEC mode using RSA as Server Host Key.

The SSH session connected to the specified IP address has timed out.

Informational

SSH session closed by user from src IP ip-address, MAC mac-address in PRIVILEGED EXEC mode.

Indicates SSH logout has occurred due to termination. Similar message is logged for “user exec” mode.

Informational

SSH session killed for user src IP ip-address, MAC mac-address in PRIVILEGED EXEC mode.

Indicates SSH logout has occurred because the session was killed.

Informational

SSH session 1 from src IP ip-address Algorithm Negotiation Failed

SSH session not established for specified source due to negotiation failure.

Informational

SSH Server session 1 initiated key-exchange due to MAX DATA

SSH session key re-exchange was initiated because the specified data limit was reached.

Informational

SSH Server session 1 initiated key-exchange due to MAX Time

SSH session key re-exchange was initiated because the specified time limit expired.

Informational

Super user login success in console session.

Indicates user has logged in with super user password.

Informational

Console timed out by super from PRIVILEGED EXEC mode

Indicates the timeout of a user session at the local console.

Informational

username : user is disabled

Specified user account is locked.

Informational

username : user is enabled

Specified user account has been unlocked.

Informational

Console login by user user failed

Console login for the specified user failed, possibly due to incorrect username or password.

Informational

SSH access by user user from src IP ip-address rejected, # attempt(s)

SSH login for the designated user has failed after the specified number of attempts.

Informational

Logging CLI_CMD operation enabled by user from console session.

"logging cli-command" by user from console.

Indicates audit log logging cli-command command is enabled.

Informational

Logging CLI_CMD operation disabled by user from console session.

Indicates audit log logging cli-command command is disabled.

Informational

"reload" by un-authenticated user from console

Indicates initiation of device reload through console.

Informational

<Device_Hostname> SSL session from src IP: ip-address failed due to remote disconnect.

Indicates SSL connection failure.

Informational

SSL server ip-address:port_number is now connected

Indicates encrypted syslog or radius server is connected in the server end.

Informational

SSL server ip-address:port_number is now disconnected

Indicates encrypted syslog or radius server is disconnected in the server end.

Informational

SSH login by user from src IP ip-address from src MAC mac-address to USER EXEC mode using RSA as Server Host Key.

Device# scp -t file: secondary.sig

Device# transfer to device completed

SSH logout by user from src IP ip-address from src MAC mac-address from USER EXEC mode using RSA as Server Host Key.

Indicates the SCP transfer.

Informational

yyyy month dd hh:mm:ss

Indicates the timestamp format that is used in syslog messages.

Informational

device(config) # write memory

Message: "write memory" by user from console.

Audit log will display the commands in expanded form.

Informational

console login by user to USER EXEC mode.

Displays all "login" events including the user and session details. Similar message is logged for “logout” events and “privileged exec” mode.

Informational

Interface ipsec_tnnl <tunnel_id>, state up

The IPsec tunnel interface has come up .

Informational

Interface ipsec_tnnl <tunnel_id>, state down <reason>

The IPsec tunnel interface has gone down.

Reasons that may be displayed:

  • clear IKE SA
  • clear IPSEC SA
  • IKE session down
  • IPSEC session down
  • tunnel source interface down
  • tunnel no destination orute
  • administratively brought down
  • IPSEC card down
  • switchover and failover

Informational

CLI CMD: "ip ssl profile <profile_name>" by user from console

Indicates SSL profile is created.

Informational

CLI CMD: "trustpoint < trustpoint_name>" by user from console

Indicates trustpoint is associated with SSL profile.

Informational

CLI CMD: "remotedomain <remotedomain>" by user from console

Indicates remotedomain is associated with SSL profile.

Informational

Configuration for radius-server host ip-address has been enable

Added radius server host configuration.

Informational

CLI CMD: “ no radius-server host ip-address " by user from console

Removed radius server host configuration.

Informational

System: Syslog server ip-address added by user from console session.

Added syslog server host configuration.

Informational

System: Syslog server ip-address deleted by user from console session.

Removed syslog server host configuration.

Informational

SSL Handshake to server ip-address:port_number is failed due to Bad certificate

The server certificate is not valid for the following reasons.

  • Invalid/revoked server certificate
  • CN mismatch
  • SAN mismatch

Notification

IKEv2: Phase1 failed . Hostname mismatch Source <TunnelSource> Destination <TunnelDestination> VRF <VRFID> Tunnel <TunnelID>

Configured DN value doesn't match peer certificate remote DN.

Informational

ACL: List <Access-list name> permitted <Protocol> <sourceIP> <source port number> (Ethernet <Ethernet interface> <source MAC address> -> <destination IP><Destination Port Number >

The traffic from given <source IP, source port> to <destination IP, destination port> is permitted by the given <Access-list name>, which is applied on the given Ethernet interface.

Informational

ACL: List <Access-list name> denied <Protocol> <sourceIP><source port number>(Ethernet <Ethernet interface> <source MAC address> -> <destination IP><Destination Port Number>

The traffic from given <source IP, source port> to <destination IP, destination port> is denied by the given <Access-list name>, which is applied on the given Ethernet interface.