Cisco :: 4402 - How To View Logs Of Disabled MAC Addresses
Jan 4, 2011
I have a Wireless LAN Controller 4402 and WCS 7.0, and I have a few MAC addresses that are "disabled" due to policy violations. How can I view a log or a report that will show me if these MAC addresses are still attempting to connect?
View 3 Replies
ADVERTISEMENT
Oct 16, 2012
view a history of IPs that have connected to my computer. Specifically those that accessed my computer through a remote desktop connection? I believe I can check and see the ip while someone is connected but not after they disconnected.
View 1 Replies
View Related
Sep 15, 2010
Recently we've been receiving the following log entries on our WLC 4402. Unfortunately Cisco's documentation is less than useful as to what this message means or what could be causing it. [code]
View 9 Replies
View Related
May 18, 2011
I am having trouble viewing all the Administration logs in ACS View. I have my Local Log Target set to a Maximum log retention period of 90 days. In ACS View I can display authentications that go back 90 days + However when I try and display the "ACS_Configuration_Audit" in View and perform a Custom query that goes back 90 days it will only display about 35 days of Admin logs.I know the logs are there because when I go into CLI and do a search like "show logging | i "ObjectType=Administrator Account" the Administration logs go back over a year.why ACS View cannot display all the Admin logs?The ACS is running v5.1.0.44 Patch 6 (Also experiencing this in a v5.2 ACS as well)
View 2 Replies
View Related
Mar 6, 2012
We have below queries regarding new version of ACS 5.3.
a) Is it possible to view real time logs for AAA clients and for ACS administrator?
b) Is it possible to track each and every change record for ACS Administrators and sessions in ACS . Ex addition and deletion of commands in command sets. As of now, we are able to see that config has changed by ACS admin but not able to see which commands are changed (Added or Removed)
c) As per user guide of ACS 5.3, we have an option for creating customized reports but unfortunately we are not able to see same option in ACS 5.3 GUI. Need confirmation on the same.
d) Is it possible to do configuration changes for ACS via Command line.
View 1 Replies
View Related
Apr 16, 2012
We have a Cisco 4404 WLC and and about 70 Cisco 1131 APs. I am very new to the Cisco WLC and I need to know how to view its AP registration and unregistration logs. We have a AP that has unregistered and we can't seem to find what switchport it was attached to. It would be useful to know the IP address and ideally any CDP information it had. Unfortunately you can only view this information in the WLC if the AP is registered, but at this point it is not.
View 2 Replies
View Related
Apr 12, 2013
I am trying to setup 4 cameras to view with remote live view. I set up my server with IP addresses of 192.168.1.80 .... 85. The screen has only the option for 1 video channel. I have seen on-line screen shots that have options for channel 1 through 8. I want to assign each camera to a different channel so I will be able to use remote live view to show all 4 cameras at the same time. I can only show one at a time. Do I need a different version than 3.3 or some obscure windows 7 setting?
View 5 Replies
View Related
Oct 8, 2012
In setup for old RV042 (V1), when updating / adding Mac addresses, the table is always sorted by IP addresses. But in the new oneRV042 (V3) I have, even with latest firmware 4.2.1.02 the list is random, thereby increasing the chance of user entering DUPLICATE IP addr with diff Mac addr. That will result in conflict.If the firmware sorts the DHCP entries by ip addresses, user would be able to catch duplicate ip errors even if the system does not flag the errors. All Cisco smart engineers can you all get the dhcp entries SORT by ip addresses.
View 2 Replies
View Related
Dec 22, 2012
how to turn off this logs??
*Mar 2 13:26:07.919: %SEC-6-IPACCESSLOGP: list 101 denied udp 79.2.199.68(57143) -> x.x.x.x (34803), 1 packet
Router#
*Mar 2 13:26:09.766: %SEC-6-IPACCESSLOGP: list 101 denied tcp 108.15.116.235(63864) -> x.x.x.x (34803), 1 packet
Router#
*Mar 2 13:26:11.276: %SEC-6-IPACCESSLOGP: list 101 denied udp 24.130.2.212(26935) -> x.x.x.x (34803), 1 packet
View 3 Replies
View Related
May 24, 2012
I cannot read ACS 5.3 logs from my WCS. I have the ACS server added to the WCS. Below is the message I'm getting:
Unable to connect to any ACS View Server.Failed to access the WSDL at: { URL}. It failed with: {URL}. Do I need to install any special module on the ACS to support this?
View 1 Replies
View Related
Jun 16, 2011
I have a question about VPN Concentrator FTP Backup configuration to get logs on FTP server. I have configure FTP Backup with all details but I still do not see any logs on FTP server. Do you know what could be the issue? I have never used Concentrator and not sure what needs to be done to get in working condition. I am using VPN Concentrator 3015 series.
View 5 Replies
View Related
Nov 4, 2012
I am running two ASA 5520 routers synched up with eachother. I had a massive connectivity issue this weekend that I am investigating. Now I have figured out how to get the live logging but I need to know how to get the old logs from my router.
View 4 Replies
View Related
Sep 6, 2011
I have 3 ACS servers placed throughout N. America. I it set up so that ACS01 is primary and ACS02 and ACS03 are secondary. When i look at the logs for passed/failed authentications in radius or tacacs I cannot see anything from ACS03 logging. This is weird because just a few weeks ago it worked perfectly. In fact, ACS03 is the most active server since this site is using it for wireless phones and tacacs and the other 2 are just using ACS for wireless networking. I went through the log settings and every server is set up the same as the others (except the primary) so it should be logging ACS03 the exact same as 01 and 02.Anyway it seems like a small problem but i need the logs to work correctly to properly administrate security.
View 1 Replies
View Related
Aug 31, 2011
There was a interface down in one of critical devices in the network.that particular log is not captured by the ciscoworks(DFM-alerts).
View 1 Replies
View Related
Jan 1, 2013
My iphone started resetting the connection every 2 minutes today. I noticed that the date maximum is Dec 31, 2012. My logs are getting messed up, and NTP isn't setting. Is there a firmware update for REV E3?? I'm at 5.10 right now.
View 11 Replies
View Related
Oct 16, 2012
I want to secure our WLAN via Web Authentication with our new Cisco 2504 WLC. But where do i find user activity logs?
View 2 Replies
View Related
May 10, 2012
We recently had to rebuild our ACS server. Now when we have an 802.1x authentication failure and look at the RADIUS logs for the specific user, it does not show us the MAC address of the device the user tried to login with. We use this all the time because users have PDAs and other mobile devices that they save their passwords on. Then when they change their domain password on their laptop, they don't change it on their PDA which then tries to authenticate them using the wrong password and eventually locks them out. We need to see the MAC address so we can pinpoint which device is causing the lockout. The report I am generating is when you go to this location: Monitoring & Reports > ... > Reports > Catalog > User > User_Authentication_Summary
View 4 Replies
View Related
Jul 16, 2012
I have hardware version 2 and firmware 3.0.2.01 (latest firmware available for this hardware version I believe) and I cannot get it to email me logs. I have entered my outlook address and our SMTP server.The log says that it's failing each time it attempts. I have scoured the internet and I cannot find a solution that will work for me. I have found some talk of adjusting an MTU setting which is supposed to be located under the firewall / general tab.
View 1 Replies
View Related
Apr 14, 2013
I have turned on 'Local log' and 'output blocking event log' on my WRVS4400N v2 with latest fw.When I am clicking 'view log' button I can't see anything in empty fields. When I am trying to change logs genre I have empty fields all time.
View 1 Replies
View Related
Nov 15, 2012
I am using a 2851 router in mpls network. We had a power shut down activity recently and post to that i could not find any logs in the router.
View 4 Replies
View Related
Aug 29, 2011
I am trying to setup logging on my router. I want to use my gmail account / gmail SMTP server to send emails.
Does the router support TLS for SMTP?
Oh - and I also get the "critical error" page. I get it when I try to un-check the send logs checkbox in the remote logging management page.
View 5 Replies
View Related
Dec 3, 2012
I have a 5508 wireless lan controller we have two SSID configured Profile Name : Corporate and Guest When I go look at the Most Recent Traps all I see is Client with Mac address blah has joined your corporate, this goes on for sometime. But I am unable to see any of the Guest logs joining the network, I have since then grabbed my laptop and connected to the guest log. I still dont see any logs in Most Recent Traps for the Guest SSID WLAN configuration, I then blocked my Mac address and tried to connect again, No logs. I need to also montior the guest network is there some special tick box I need to apply for this to work? Once the guest is connected I can view them in the clients list but it never shows them on MOST RECENT TRAPS but I want to see the guests account connecting or failing to connect as we currently have a rogue device annoying me.
View 3 Replies
View Related
Jan 6, 2013
what is the meaning of the following log messages on Cisco 7604 Core routers. The Core router is configured with 2 STM card configurations with Vlan assignments: [code]
View 3 Replies
View Related
Oct 13, 2012
We are using almost 10 Nexus 5k in our DC currently we are getting same error logs in all Nexus 5k." ntpd[4746]: ntp:time reset +0.279670 s " ,Is it major error or just for reset time?
View 1 Replies
View Related
Nov 28, 2011
I am receiving trace back logs in the 881G with 3G module. And after reload, the router is going to Initial Config. mode. What the latest IOS is?
Current IOS I am using is c880data-universalk9-mz.151-1.T3.bin. Any better IOS for complete efficient use of the PCEX-HSPA-G Module ?
View 5 Replies
View Related
Jan 15, 2012
Noticed tacacs authorization logs when you change password for a user ?? in authorization logs I can see the new password but same I can not see in accounting logs ? is it a normal behaviour ?? or do we need to do something to hide the password in authorization logs ?
For example if i type command username xyz priv 15 secret cisco 123
I see this command in accounting logs as uername xyz oriv 15 secret *** where as in tacacs authorization logs it shows username xyz priv 15 secret cisco 123
View 1 Replies
View Related
Jan 31, 2012
On a RV220W (1.0.3.5) I keep seeing the following error in the logs multiple times:
[Kernel][KERNEL] ERROR:endChantRecv: protocol PNAC returned !OK
What this error is all about and how to fix it?
View 6 Replies
View Related
Sep 13, 2012
I've noticed in the mornings lately when I get up around 6 am my internet will not work. Not on wireless or on my desktop. I decided I'd log into the router to see if there was a firmware update or anything. I had checked the logs and there are quite a few entries relating to DoS. I googled around and saw that it could be some sort of packet loss and the router is mistaking it for some sort of DoS attack. And that due to it not showing up multiple times every second it likely isn't a DoS attack. Here is a few from the logs:
[code].....
View 4 Replies
View Related
Jun 13, 2011
The URL field in the web access log has a length of 70 characters. Is there any way to increase is[INFO] Mon Jun 13 21:30:30 2011 Website1234567890012345678900123456789001234567890012345678900123456789001234567890 accessed from 192.168.xx.xx
View 2 Replies
View Related
Feb 8, 2011
Any way to get the DIR-655 to e-mail logs? I have all the e-mail settings set properly, but when I request the logs to be e-mailed, I never get anything. Its not in a spam folder either.I do have the DIR-655 behind a 2wire router/DSL modem. I don't know if this is the problem, but I can send and receive e-mails from my computer which is connected to the DIR-655, so I don't think that is the problem.
View 6 Replies
View Related
Apr 2, 2013
I'm getting below msgs in my ZBFW logs on my test router. .Apr 2 23:09:43: %FW-6-DROP_PKT: Dropping icmp session 115.186.192.153:0 10.40.2.100:0 on zone-pair ZP-OUTSIDE-INSIDE class class-default due to DROP action found in policy-map with ip ident 0
The bit I'm curious about is that I am NOT NAT-ting any ICMP. Hence why is the ZBFW even triggering against the LAN IP? It should only activate after NAT according to order of operations (and hence why unlike CBAC you put the inside local IP not the outside global IP).....
If the ICMP was directed at the WAN interface (not the 10.40.2.100 internal IP) then it is allowed, but morever even if blocked it should be logged against my WAN IP (which is publicly routable not a 10.x internal).
View 2 Replies
View Related
Mar 23, 2012
I have cisco ACS 4.2 (1) build 15 working fine, but it can save historic logs for Passed Authentications, Failed attempts. etc.
View 1 Replies
View Related
Apr 17, 2011
I have a problem with ASA 5510 8.0(4) This is a remote-access VPN setup and it's functional, no problems here...
But I keep getting logs like this every few seconds:
Group = <censored>, Username = <censored>, IP = <censored>, Reaper overriding refCnt [0] and tunnelCnt [0] -- deleting SA!
Group = <censored>, Username = <censored>, IP = <censored>, SA lock refCnt = 0, bitmask = 00000080, p1_decrypt_cb = 0, qm_decrypt_cb = 0, qm_hash_cb = 0, qm_spi_ok_cb = 0, qm_dh_cb = 0, qm_secret_key_cb = 0, qm_encrypt_cb = 0
View 1 Replies
View Related