Syslog Messages in Korean CC Mode

The following table lists some of the syslog messages in Korean CC mode.

Syslog Messages in Korean Common Criteria Mode

Audit Event Audit Content Sample Audit

Start-up and shut-down of the audit functions

Create, delete, and import the cryptographic keys

User name

Shut-down:

2024-04-12T20:02:49Z ICX7550 - - [meta sequenceId=10] BOM CLI CMD: "reload" by super user from console

Start-up:

2024-04-12T20:00:34Z ICX7550 ICX7550 - System [meta sequenceId=9] BOM System: Interface ethernet mgmt1, state up by Username

Key Generation:

2024-03-14T19:47:41Z example.com ICX7550 BOM Crypto: Successfully generated EC key pair by Username

Key Deletion:

2024-03-14T19:56:37Z example.com ICX7550 BOM Crypto: EC key pair is successfully deleted by Username

Importing of Cryptographic Keys:

2024-03-22T13:36:35Z example.com ICX7550 BOM Download: CERTIFICATE/KEY DOWNLOAD START by Username

2024-03-22T13:36:39Z example.com ICX7550 BOM Download: CERTIFICATE/KEY DOWNLOAD COMPLETED by Username

Resetting Passwords User name

Resetting Passwords:

2024-04-03T17:14:28Z:I: example.com - - [meta sequenceId=480] BOM CLI CMD: "username testuser password ....." by admin user from ssh

Session establishment Secure Channel Identifier (SCI) 2024-04-28T17:26:59Z ICX7550 ICX 7550 - General [meta sequenceId=58] BOM MACsec: communication is now secured for port 1/3/3 Session SCI - 3420e30008290082, CKN - acbf98acd980bf385193871209184001
e1: Creation and update of Secure Association Key e1: Creation and update times 2024-04-28T17:26:59Z ICX7550 ICX7550 - General [meta sequenceId=60] BOM MACsec: new SAK generated for port 1/3/3
e4: Creation of Connectivity Association (per TD0509) e4: Connectivity Association Key Names (per TD0509) 2024-04-28T17:26:59Z ICX7550 ICX7550- General [meta sequenceId=58] BOM MACsec: communication is now secured for port 1/3/3 Session SCI - 3420e30008290082, CKN - acbf98acd980bf385193871209184001
Configuration of a new time server Removal of configured time server Identity any new/removed time server

Added:

2024-04-29T19:24:59Z ICX7550 - - [meta sequenceId=17] BOM CLI CMD: "server 192.168.144.254 key ..... 4 " by super user from console

Removed:

2024-04-29T19:24:53Z ICX7550- - [meta sequenceId=14] BOM CLI CMD: "no server 192.168.144.254 key ..... 4 " by super user from console

Establishing an SSH session User name SYSLOG: <14>1 2025-04-07T04:15:47Z ICX7550 ICX7550 - Security [meta sequenceId=30] BOM Security: SSH server Enabled by super user from console session
Failure to establish an SSH session. Reason for failure.

2025-04-04T05:14:51Z:I: Test121113111aaa1 ICX7550 - General [meta sequenceId=18] BOM Security: ssh login by cli from src IP 10.246.201.17, src MAC c0c5.206b.5712, src PORT 48390 to dest IP 10.176.156.34, dest PORT 22 to USER EXEC mode

2025-04-04T05:15:11Z:I: Test121113111aaa1 ICX7550 - General [meta sequenceId=19] BOM Security: ssh logout by cli from src IP 10.246.201.17, src MAC c0c5.206b.5712, src PORT 48390 to dest IP 10.176.156.34, dest PORT 22 from USER EXEC mode

SYSLOG: <14>1 2025-04-04T05:15:59Z Test121113111aaa1 ICX7550 - General [meta sequenceId=21] BOM sshd: SSH access by user cli from src IP 10.246.201.17 rejected, 1 attempt(s)

SYSLOG: <14>1 2025-04-07T04:15:42Z ICX7550 ICX7550 - Security [meta sequenceId=29] BOM Security: SSH server Disabled by super user from console session

Added new syslog.
Enabling SNMP server
  SYSLOG: <14>1 2025-04-07T04:15:58Z ICX7550 ICX7550 - System [meta sequenceId=32] BOM SNMP: SNMP server Enabled by super from CONSOLE session.
Disabling SNMP server   SYSLOG: <14>1 2025-04-07T04:15:55Z ICX7550 ICX7550 - System [meta sequenceId=31] BOM SNMP: SNMP server Disabled by super from CONSOLE session.
Added new syslog.
Enabling TFTP
  SYSLOG: <14>1 2025-04-07T04:16:13Z ICX7550 ICX7550 - Security [meta sequenceId=34] BOM Security: TFTP service enabled by super user from console session
Disabling TFTP   SYSLOG: <14>1 2025-04-07T04:16:11Z ICX7550 ICX7550 - Security [meta sequenceId=33] BOM Security: TFTP service disabled by super user from console session
Added new syslog.
Enabling syslog
  SYSLOG: <14>1 2025-04-07T04:16:32Z ICX7550 ICX7550 - System [meta sequenceId=36] BOM System: Syslog operation enabled by super from CONSOLE session.
Disabling syslog   SYSLOG: <14>1 2025-04-07T04:16:27Z ICX7550 ICX7550 - System [meta sequenceId=35] BOM System: Syslog operation disabled by super from CONSOLE session.
Added new syslog.
Enabling SCP
  SYSLOG: <14>1 2025-04-07T04:16:53Z ICX7550 ICX7550 - Security [meta sequenceId=37] BOM Security: SCP service Enabled by super user from console session
Disabling SCP   SYSLOG: <14>1 2025-04-07T04:16:59Z ICX7550 ICX7550 - Security [meta sequenceId=38] BOM Security: SCP service Disabled by super user from console session
Unsuccessful login attempt limit is met or exceeded. Origin of the attempt (e.g., IP address).
Added the new syslog and removed the old one [

2024-04-13T15:17:23Z ICX7550-48P Router ICX7550_Router - General [meta sequenceId=16] BOM sshd: username TestUser is disabled ]

SYSLOG: <14>1 2025-04-04T05:15:59Z Test121113111aaa1 ICX7550 - General [meta sequenceId=21] BOM sshd: SSH access by user cli from src IP 10.246.201.17 rejected, 1 attempt(s)
All use of identification and authentication mechanism. Origin of the attempt (for example, IP address).

SSH Success:

2024-04-11T13:23:31Z ICX7550 ICX7550 - General [meta sequenceId=51] BOM Security: ssh login by super from src IP 192.168.144.254 from src MAC 0015.5d90.1701 to USER EXEC mode

SSH Password Failure:

2024-03-25T16:44:51Z ICX7550 ICX7550 - General [meta sequenceId=4] BOM sshd: SSH access by user admin from src 192.168.144.254 rejected, 0 attempt(s)

SSH Pubkey Failure:

2024-04-20T17:42:16Z ICX7550 ICX7550 - General [meta sequenceId=5] BOM sshd: Failed publickey for admin from 192.168.144.254 port 42462 ssh2

Console Success:

Added this new syslog and removed the old one [ 2024-04-11T13:22:16Z ICX7550-48P Router ICX7550_Router - General [meta sequenceId=17] BOM Security: console login by super to PRIVILEGED EXEC mode ].

SYSLOG: <14>1 2025-04-15T11:14:49+05:30 ICX7550-48F ICX7550 - General [meta sequenceId=29] BOM Security: console login by cli to PRIVILEGED EXEC mode

Console Failure:

Added this new syslog and removed the old one [ 2024-03-20T19:06:12Z example.com ICX7550_Router BOM login: Console login by user admin failed ].

SYSLOG: <11>1 2025-04-15T11:14:45+05:30 ICX7550-48F ICX7550 - Security [meta sequenceId=28] BOM Security: Access to PRIVILEGED EXEC mode via console session is rejected, initated by cli
Any attempt to initiate a manual update using SCP.

2024-04-06T19:52:50Z ICX7550 - - [meta sequenceId=184] BOM CLI CMD: "copy scp flash 192.168.144.254 /tmp/SPR10010devufi.bin primary" by super user from console

2024-04-06T19:52:57Z ICX7550 ICX7550 - - [meta sequenceId=185] BOM Download: COPY IMAGE TO FLASH START by Username

2024-04-06T19:54:20Z ICX7550 ICX7550 - - [meta sequenceId=186] BOM Download: FIPS IMAGE VERIFICATION PASSED AND STORED IN FLASH by Username

2024-04-06T19:54:20Z ICX7550 ICX7550 - - [meta sequenceId=187] BOM Download: COPY APPLICATION IMAGE FROM BUNDLE START by Username

2024-04-06T19:54:20Z ICX7550 ICX7550 - - [meta sequenceId=188] BOM Download: COPY BOOTROM IMAGE FROM BUNDLE START by Username

2024-04-06T19:54:41Z ICX7550 ICX7550 - - [meta sequenceId=189] BOM Download: COPY BUNDLE IMAGE COMPLETED by Username

Added this new syslog.
Any attempt to initiate a manual update using TFTP.
  SYSLOG: <14>1 2025-04-07T04:21:26Z ICX7550 ICX7550 - - [meta sequenceId=43] BOM Download: SIGNATURE DOWNLOAD STARTED by super

SYSLOG: <14>1 2025-04-07T04:21:36Z ICX7550 ICX7550 - - [meta sequenceId=45] BOM Download: COPY IMAGE TO FLASH START by super

SYSLOG: <14>1 2025-04-07T04:21:53Z ICX7550 ICX7550 - - [meta sequenceId=46] BOM Download: FIPS IMAGE VERIFICATION PASSED AND STORED IN FLASH by super

SYSLOG: <14>1 2025-04-07T04:21:53Z ICX7550 ICX7550 - - [meta sequenceId=47] BOM Download: COPY APPLICATION IMAGE FROM BUNDLE START by super

SYSLOG: <14>1 2025-04-07T04:21:53Z ICX7550 ICX7550 - - [meta sequenceId=48] BOM Download: COPY BOOTROM IMAGE FROM BUNDLE START by super

SYSLOG: <14>1 2025-04-07T04:22:30Z ICX7550 ICX7550 - - [meta sequenceId=49] BOM Download: COPY BUNDLE IMAGE COMPLETED by super

All management activities of TSF data.

Every admin command is logged and tagged with CLI_CMD so all managment functions are covered by that. Below is an example audit:

2024-04-11T12:59:50Z ICX7550 - - [meta sequenceId=6221] BOM CLI CMD: "logging buffered 50" by super user from console.

Detected replay attempt 2024-03-09T22:48:02Z ICX7550 MACSEC: Warning! Late-Pkts[Count 5] are received Port[1/3/1]
Discontinuous changes to time - either Administrator actuated or changed via an automated process. (Note that no continuous changes to time need to be logged.) For discontinuous changes to time: The old and new values for the time. Origin of the attempt to change time for success and failure (for example, IP address).

Manual:

2024-04-12T19:26:00Z ICX7550 ICX7550 - System [meta sequenceId=2782] BOM Clock Changed from old time 14:47:39.387 Eastern Tue Apr 12 2024 to new time 19:26:00.001 Eastern Tue Apr 12 2024 by super user from console session

Initiation of update; result of the update attempt (success or failure).

Failure:

2024-04-29T17:12:17Z ICX7550 ICX7550 - System [meta sequenceId=381] BOM Download: COPY BUNDLE IMAGE VALIDATION FAILED by Username

The termination of a remote session by the session locking mechanism. 2024-02-14T13:54:05Z ICX7550 ICX7550 - General [meta sequenceId=1] BOM Security: ssh timed out by admin from src IP 192.168.144.254 from src MAC 0015.5d90.1701 from USER EXEC mode by Username
The termination of an interactive session.

Added new and removed the old syslog.
SSH:

2025-04-04T05:15:11Z:I: Test121113111aaa1 ICX7550 - General [meta sequenceId=19] BOM Security: ssh logout by cli from src IP 10.246.201.17, src MAC c0c5.206b.5712, src PORT 48390 to dest IP 10.176.156.34, dest PORT 22 from USER EXEC mode

Console:

2025-04-04T05:16:49Z:I: Test121113111aaa1 ICX7550 - General [meta sequenceId=24] BOM Security: console logout by cli from USER EXEC mode

2025-04-04T05:16:48Z:I: Test121113111aaa1 ICX7550 - General [meta sequenceId=23] BOM Security: console logout by cli from PRIVILEGED EXEC mode

(if 'lock the session' is selected) Any attempts at unlocking of an interactive session. (if 'terminate the session' is selected) The termination of a local session by the session locking mechanism. 2024-02-15T12:38:06Z ICX7550 ICX7550 - General [meta sequenceId=222] BOM Security: console timed out by admin from USER EXEC mode

Message Level in Korean Common Criteria

Message Level

Message

Explanation

Alert

Clock Changed from old time <old time> GMT+00 <old date> to new time <new time> GMT+00 <new date>

Indicates time is updated using the clock set command.

Informational

Interface ethernet mgmt1, state up

Indicates ICX device startup.

Informational

FIPS: [primary/secondary] image verification success

The image copy and verification to primary or secondary flash are successful.

Informational

FIPS: [primary/secondary] image verification failed

Image verification in primary or secondary flash has failed.

Informational

SSH login by user from src IP ip-address, src MAC mac-address to USER EXEC mode using RSA as Server Host Key.

Indicates entry into the "user exec" mode for all sessions for the mentioned user. Similar message is logged for “privileged exec” mode.

Informational

SSH logout by user from src IP ip-address, src MAC mac-address from USER EXEC mode using RSA as Server Host Key.

Indicates exit from "user exec" mode for all sessions for the mentioned user. Similar message is logged for “privileged exec” mode.

Informational

SSH timed out by admin from src IP ip-address from src MAC mac_address from USER EXEC mode using RSA as Server Host Key.

The SSH session connected to the specified IP address has timed out.

Informational

SSH session closed by user from src IP ip-address, MAC mac-address in PRIVILEGED EXEC mode.

Indicates SSH logout from “privileged exec” mode has occurred due to termination. Similar message is logged for “user exec” mode.

Informational

SSH session killed for usersrc IP ip-address, MAC mac-address in PRIVILEGED EXEC mode.

Indicates SSH logout from “privileged exec” mode has occurred because the session was killed.

Informational

SSH session 1 from src IP ip-address Algorithm Negotiation Failed

SSH session not established for specified source due to negotiation failure.

Informational

Super user login success in console session.

Indicates user has logged in with super user password.

Informational

Console timed out by super from PRIVILEGED EXEC mode

Indicates the timeout of a user session at the local console.

Informational

username : user is disabled

Specified user account is locked.

Informational

Console login by user user failed

Console login for the specified user failed, possibly due to incorrect username or password.

Informational

SSH access by user user from src IP ip-address rejected, # attempt(s)

SSH login for the designated user has failed after the specified number of attempts.

Informational

Logging CLI_CMD operation enabled by user from console session.

"logging cli-command" by user from console.

Indicates audit log logging cli-command command is enabled.

Informational

Logging CLI_CMD operation disabled by user from console session.

Indicates audit log logging cli-command command is disabled.

Informational

"reload" by un-authenticated user from console

Indicates initiation of device reload through console.

Informational

<Device_Hostname> SSL session from src IP: ip-address failed due to remote disconnect.

Indicates SSL connection failure.

Informational

SSH login by user from src IP ip-address from src MAC mac-address to USER EXEC mode using RSA as Server Host Key.

Device# scp -t file: secondary.sig

Device# transfer to device completed

SSH logout by user from src IP ip-address from src MAC mac-address from USER EXEC mode using RSA as Server Host Key.

Indicates the SCP transfer.

Informational

yyyy month dd hh:mm:ss

Indicates the timestamp format that is used in syslog messages.

Informational

device(config) # write memory

Message: "write memory" by user from console.

Audit log will display the commands in expanded form.

Informational

console login by user to USER EXEC mode.

Displays all "login" events including the user and session details. Similar message is logged for “logout” events and “privileged exec” mode.

Informational

Configuration for radius-server host ip-address has been enable

Added RADIUS server host configuration.

Informational

CLI CMD: “ no radius-server host ip-address " by user from console

Removed RADIUS server host configuration.

Informational

System: Syslog server ip-address added by user from console session.

Added syslog server host configuration.

Informational

System: Syslog server ip-address deleted by user from console session.

Removed syslog server host configuration.