Cisco :: LMS 4.0.1 / Understanding Change Audit Report?

Jun 27, 2011

I need to understand why change audit report reports an unused username Name of the user who performed the change. This is the name  entered when the user logged in. It can be the name under which the LMS  application is running, or the name using which the change was performed on the  device. #The User Name field may not always reflect the user name. The  User Name is reflected only when: A config change was performed using LMS. #A config change was performed outside of LMS, but the  network has username-based AAA security model, wherein authentication is  performed by an AAA server, which could be TACACS/RADIUS or local.

View 2 Replies


ADVERTISEMENT

Cisco :: Ciscoworks LMS3.2 Not Showing Latest Configuration / Change Audit Report

Dec 19, 2012

My cisco works LMS3.2 is  not showing recent configuration of my Cisco devices. also it dont show any change report on last 24 hours or even if i select x number of day, looks like its not saving any changes made on devices.
 
today i logged in and cisco ASA was showing this in status as well Configuration Last Archived Time    May 03 2012 11:27:46 EDT  on checking i could see it is same date when cisco ASA was added in cisco works. do i need to click some where for auto update configuration changes and latest confoguration in cisco works setting?

View 1 Replies View Related

Cisco :: LMS 4.1 Device Change Audit Lists Wrong Users?

Aug 14, 2011

I have noticed that under the Device Change Audit list under the configuration dashboard. LMS lists the wrong user for the last change. For example. User ABC performed a change on a switch yesterday but switch shows user XYZ has performed the change.
 
e.g.
 
SwitchA
 
! Last configuration change at 16:27:06 AEST Mon Aug 15 2011 by ABC
 
User XYZ then performs changes on switchB, switchC. These show up correctly. but the change on switchA shows user XYZ instead of ABC.
 
User XYZ has never logged into the switchA in question.

View 1 Replies View Related

Cisco :: 4507R-E And RME Config Change Report?

Aug 22, 2011

We have a new 4507R-E Switch which RME keeps reporting as "CONFIG_CHANGE" each evening. When you click to see the change, the only thing that has changes is the "ntp clock-period".
 
However, we have configured "ntp clock-period" as an exclude command in RME Config Managment.

View 1 Replies View Related

Cisco :: LMS 4.1 - Change Server Name In Report Emails

Feb 13, 2012

Currently, my report links are displaying the server as "lms" instead of "lms.domain.net".  Where do I change this within LMS?

View 2 Replies View Related

Network Audit Tools?

Oct 10, 2012

me what are the best Free tools to do a Network Audit (Thoughput, speed linksswitchs usage, analyse network topology.. etc)

View 7 Replies View Related

Cisco WAN :: WS-C6509-E - How To Enable Audit Log To Server

Apr 10, 2013

In our network we use cisco WS-C6509-E (R7000) Backbobe switch. We want to route syslog to log server.But I couldn't do it. How can solve this problem?

View 7 Replies View Related

Cisco Security :: PIX 515E Logging For Audit

Oct 17, 2011

We have a PIX 515E running ver 6.3 and we want to implemente some sort of logging to keep track of who/when logs in to the PIX and if they make any config changes or to the file system. All of this is for forensic purposes in the future. I have already looked at some PIX docs but I don´t seem to find what I am lokking for.

View 1 Replies View Related

Cisco AAA/Identity/Nac :: How To Enable ACS 5.2.0.26 Configuration Audit

Oct 12, 2011

ACS and i would like to know how to enable the "Configuration Audit" for someone login to my network devices using their ACS login and i can monitor what they did on it.
  
ACS Version : 5.2.0.26

View 6 Replies View Related

Cisco VPN :: Audit Users On Old 3060 Concentrators?

Sep 13, 2012

We are trying to finally get rid of a couple old 3060 concentrators and would like to see how many active connections are still on.  Is there any reporting that can be seen from the concentrators? 

View 3 Replies View Related

Cisco Security :: 4.7.2 / Nac Agent Requirement Type Audit?

Feb 7, 2011

i can configure a requirement type as audit (opposed to mandatory or optional), so the client will still access the network, the user will not be notified, and the information will be sent to the cas.It is possibile to generate an email or similar automated process to notify administrators on these audits?
 
(version in use 4.7.2)

View 2 Replies View Related

Cisco :: Audit All Input / Output Of Switch 1900

Jan 10, 2012

Sometimes our network lag and i thing there is a computer making this problem. i'd like to audit all input output of all port of a Catalyst 1900. all i manage to do is to enter to the console menu via Telnet.. once here, i try monitoring but i'm afraid to do a bad thing :

     Catalyst 1900 - Main Menu
 
     [C] Console Settings
     [S] System
     [N] Network Management
     [P] Port Configuration

[Code]...

View 2 Replies View Related

Understanding Subnetting And Classes?

Dec 8, 2012

I am currently trying to understand Subnetting via CCNA. My progress is going well,I understand the class below:

Class A 0-127 Max IP 2^24 = 16777216
Class B 128-191 Max IP 2^16 = 65536
Class C 192-223 Max IP 2^8 = 256

However I have seen an example from an ip calculator website, and noticed this :

Address: 192.168.1.0 11000000.10101000 .00000001.00000000
Netmask: 255.255.0.0 = 16 11111111.11111111 .00000000.00000000
Wildcard: 0.0.255.255 00000000.00000000 .11111111.11111111
=>
Network: 192.168.0.0/16 11000000.10101000 .00000000.00000000 (Class C) - I would have thought this would have been Class B?
Broadcast: 192.168.255.255 11000000.10101000 .11111111.11111111
HostMin: 192.168.0.1 11000000.10101000 .00000000.00000001
HostMax: 192.168.255.254 11000000.10101000 .11111111.11111110
Hosts/Net: 65534 (Private Internet)

Is this an invalid IP/masks as the max hosts is 65534 (which should be class B?). If so shouldnt the IP address range from 128-191- eg 172.16 (I know that CIDR is the amount of 1's. ).What calculates the class is it the netmask or the range of the first octet?

View 1 Replies View Related

Cisco :: 5508 / NCS Prime 1.3 Controller Audit Status Mismatch?

May 14, 2013

When performing an audit from NCS Prime 1.3 on our 5508 controllers (500 lic)  we are getting mismatch messages from many of our 3602i AP's that say the following...
 
(Type)Configuration Name     Audit Status              Attribute           Prime Infrastructure Value     Controller Value
 (AP APname, Interface) 802.11a/n     Mismatch     Spectrum Intelligence      true                                       false
  
These AP's are not configured as Spectrum Intelligence on the controllers, rather as local. It seems that NCS believes that they are supposed to be SI. We have refreshed the config from controller many times but this does not change. The 5508's run v.7.2.111.3 Is there a change I can make on NCS or otherwise to make this mismatch go away? Is this a bug? It is not causing any problems (that we can see) but as most would rather not have these mismatches.

View 2 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.4 - Audit Logs Operated By Secondary Instance?

Mar 28, 2013

I'm using ACS 5.4p2 within distributed systems: one primary and one secondary instance.For now, primary instance is acting as Log Collector server and I can see any AAA audit logs.

When the primary instance fails I can authenticate successfully using the secondary instance.However, when primary instance comes back, I'm not able to see any audit logs operated by secondary.

View 9 Replies View Related

Cisco :: Understanding Route Summarizing And Network?

Jul 19, 2012

I have four networks:

172.19.0.0/16
172.20.0.0/16
172.21.0.0/16
172.22.0.0/16

I understand that the summarize route is 172.16.0.0 (255.248.0.0)However I'm trying to understand which other networks fall under this route and how

View 2 Replies View Related

Cisco Firewall :: ASA 5505 / Understanding NAT For Both Version 8.2 And 8.3

Mar 1, 2013

ASA 5505 Version 8.2 or older nat (inside) 1 10.0.0.0 255.255.255.0nat (INTF4) 1 10.0.4.0 255.255.255.0nat (INTF5) 1 10.0.5.0 255.255.255.0nat (INTF6) 1 10.0.6.0 255.255.255.0nat (INTF7) 1 10.0.7.0 255.255.255.0global (outside) 1 209.165.200.235-209.165.200.254 netmask 255.255.255.224global (outside) 1 interface
 
I believe this setup does the following. The inside interface and interfaces 4,5,6,and 7 will translate using this line....

global (outside) 1 209.165.200.235-209.165.200.254 netmask 255.255.255.224

and if the addresses run out is will start using the ouside interface IP address to translate, so traffic is not disrupted and is based on the line of configuration.....

global (outside) 1 interface
 
My question, does it do this because of the order of the configuration..
 
global (outside) 1 209.165.200.235-209.165.200.254 netmask 255.255.255.224global (outside) 1 interface
 
or would it do it that way even if it was like this?
 
global (outside) 1 interfaceglobal (outside) 1 209.165.200.235-209.165.200.254 netmask 255.255.255.224
 
and if so why?Now let's convert the above configuration to ASA 5505 Version 8.3 or newer.
 
object network OUTSIDE-NAT-POOLrange 209.165.200.235 209.165.200.254object network INTERNAL-SEGMENTSsubnet 10.0.0.0 255.255.248.0nat (any,outside) dynamic OUTSIDE-NAT-POOL interface
 
My question is how does it know to use the outside interface as a backup when the OUTSIDE-NAT-POOL is depleted?Also why do I need to define the INTERNAL-SEGMENTS ? Doesn't the "any" in the (any,outside) take care of that?Also wouldn't the "any" in (any,outside) cover interface 3 or DMZ which could be an issue?

View 7 Replies View Related

Cisco WAN :: 3825 Security Bundle Understanding

Dec 22, 2010

I need to understand security bundles. I purchased a Cisco Security Bundle, Advanced Security, 64F/256D. part number CISCO3825-SEC/K9. My expectation from this device was that I will get an IOS based firewall with no need for an additional firewall module. however, the supplier is telling me that I have to buy a firewall module to use the feature. Isn't the bundle supposed to come with all I needed since is a bundle?
 
Is there any command I can use to verify if this device is really what I paid for? what can can I check for in the sh inv and sh ver commands? I don't see any information from these commands.

View 1 Replies View Related

Understanding And Configuring Windows Gateway

Mar 20, 2011

Understanding and configuring windows gateway

View 1 Replies View Related

Wifi Connection / Understanding Ip Addresses

Feb 23, 2011

When I connect to a public wi-fi connection (e.g. library, hotel, Starbucks), am I sharing the same IP address?

View 19 Replies View Related

Cisco Firewall :: ASA5505 - Understanding ASA Bundles And Licenses?

Oct 10, 2011

Any document which expalins what you need to know when looking at purchasing an ASA5505.  Which clearly describes the verious permitations and combinations of these lovely little boxes?
 
I recently purchased a basic: ASA5505-BUN-K9
 
I realise now this comes with 10 internal users, 2 ssl and no anyconnect mobility.   All these can be purchased as additional licenses.
 
Its my understanding that to support unlimmited Internal/Inside hosts - I need to purchase the L-ASA5505-SEC-PL (Security Plus License)
 
1) What is the model I should go for if I want to support unlimmited interneal.  Can a 5505 be purchased with with security plus?

View 10 Replies View Related

Cisco Firewall :: Understanding ASA 5505 Service Contracts?

Feb 18, 2013

I currently have 2 5505 SEC BUN as Primary/FO Firewalls and I am considering purchasing the ASA5510-AIP10-K9 for use as a dedicated IPS device.  Looking at [URL] I see that for service updates, CON-SU1-AS1A10K9 is available for this product, providing  "IPS Signature and Engine Updates" and "OS Updates."It is my understanding that in the ASA5510-AIP10-K9 there are 2 OS:

1. ASA OS
2. AIP SSM-10 OS
 
My question is: Are both the ASA and AIP SSM-10 able to receive "OS updates" with this service contract?

View 3 Replies View Related

Cisco Routers :: RV220W - Understanding Logs / Clearing ISR

Aug 19, 2011

Looking at the logs RV220W I can read the following lines:
 
[rv220w]Fri Aug 19 18:28:54 2011(UTC) [rv220w][Kernel][KERNEL] Clearing the ISR a800000003378400
[rv220w]Fri Aug 19 18:30:39 2011(UTC) [rv220w][Kernel][KERNEL] Clearing the ISR a800000003378200
[rv220w]Fri Aug 19 19:23:04 2011(UTC) [rv220w][Kernel][KERNEL] Clearing the ISR a800000003378e00
[ code] ....

What are they?? and what should be done ????.

View 2 Replies View Related

8080 Understanding Safety Of Open Ports

Oct 28, 2012

I am a D-I-Y type of guy and have managed to setup Apache on my LAN and make it accessible via WAN over port 80 and Tomcat on port 8080.I aim to possibly get a home web server up (will calculate the costs), but I need some questions answered about networking.

My understanding on ports are that they can be a risk if left open (which I have done) if there is no service or application listening on my side on those ports.So I take it that leaving those ports open and removing the services or applications that run on my side for these ports is a major security risk?

I noticed though that Xampp (1.8.1) does not allow requests over WAN unless I set my password for Apache. Does setting this password imply that Xampp is safe to use in a production environment?

View 1 Replies View Related

Cisco Switching/Routing :: Understanding Existing Setup With Two 3750s

Jan 10, 2013

We've recently inherited a platform with little handover and also minimal networking experience.We're going 100 miles an hour in learning, but I'm a bit confused with the idea of a L2 switch with no IP assignments to ports, so using VLANs, and a L3 switch with IP assignments. And the combination of both.We have 2 Cisco 3750 switches, along with a whole host of other hardware, so we're starting at this "gateway" to start breaking things down.

View 7 Replies View Related

Cisco Switching/Routing :: Understanding Mls Qos Queue Set Output With 3750

Apr 16, 2012

I've been  working on breaking down and understanding the default auto qos  configuration on a Cisco 3750 in the hopes of putting together a QoS  strategy that will fit our environment.  I'm having some difficulty  understanding how the "mls qos queue-set output" syntax works.
 
From another post, at [URL], the author offers the following example and explanation;
 
mls qos queue-set output <1/2> threshold 2 400 400 100 400thresshold 1: 400%
thresshold 2: 400%
thresshold 3: 100% (implicit, not configurable)
reserved: 100%
max: 400%
 
However, I'm having trouble understanding what is meant.  Here, it looks like it's saying, for example;
 
mls qos queue-set output 1 threshold 2 400 400 100 400
 
How  come there is syntax stating "threshold 2" when in the succeeding part  the 400 refers to thresshold 1 and threshold 2 again?  The syntax 400 400 is, apparently, already referring to thresshold 1 and 2, no?

View 1 Replies View Related

Cisco WAN :: 6500 / 3560 - Understanding Backplane / Throughput And Capacity

Jan 16, 2012

I have been trying to understand from a long time about the throughput capacities of variety of Cisco Routers and Switches. Have searched over a million pages on cisco.com for data sheets/documents/etc. but havent succesfully got a single document highlighting all of what i need.
 
I have got queries on the below issues:Which model of Router can support upto 2Gig's of WAN Internet connection running BGP? Any list of routers and switches supporting variety of throughput's from 1 MB to 1 GB.I have heard some experts stating "Switches don't have throughput concerns as they switch the traffic and don't need to route traffic" How true is the statement?? and if it is, Why do we require 6500's instead of 3560 Distribution Switches. 

View 3 Replies View Related

Linksys Wireless Router :: E4200v2 - Understanding USB Interface

Jan 13, 2013

I need to understand the USB interface.

View 4 Replies View Related

Cisco Switching/Routing :: 2811 Disable Audit-trail For Icmp Packets In CBAC Logging

Mar 23, 2013

I have a cisco 2811 router set up as a nat/firewall gateway for my network. I've configured it for CBAC on using ip inspect and an access list.What I want is to use audit-trail to record network traffic (which means sending syslog messages to a server) concerning established sessions from my own network to locations in the outside. If i configure this using ip inspect audit-trail and no ip inspect alert-off, the configuration looks like this: [code] which works just fine, but there is the matter of icmp packets.
 
Since i use polling software that needs to check some machines in the outside part of the network, it is only natural that several icmp sessions are established through the Inspection Rule per minute. The problem is that since these sessions are recorded along with everything else, my syslogs are flooded with these (since i am using logging trap informational) to the point that more messages are generated about icmp than all other traffic combined, especially in non-working hours.What I am asking is a way for the audit-trail to be selecively disabled for icmp, so that the outgoing (echo) &incoming (echo reply) sessions can be established without generating syslog messages.

View 1 Replies View Related

Cisco :: How To Run IOS Report In LMS 3.2

Feb 13, 2012

I'm new to CiscoWorks and I inherited the system in my new job. We are running LMS 3.2 and I want to run a report to see what versions of IOS that are running on the network.

View 3 Replies View Related

Cisco :: RME 4.3.2 - Unable To Run Eos / EoL Report?

Apr 4, 2012

Unable to run Eos/EoL report, I get error that my cisco.com credential are not valid, I verified my credential and they work fine. I'm running RME4.3.2 on Solaris 10.

View 3 Replies View Related

Cisco AAA/Identity/Nac :: Log Report In ACS 5.3?

Mar 3, 2013

I have cisco acs 5.3 appliance. Issue is, when i view tacacs accounting it only shows 100 pages of records. So first kindly tell me if this is the limitation of acs 5.3 to only show 100 pages. Secondly if i want to export the report of last 30 days, its also not showing the last 30 days.
 
How to get the report of last 30 days

View 1 Replies View Related

Cisco :: LMS 3.1 - RME Cannot Generate Syslog Report

May 17, 2011

I have an issue with rme 4.2 from LMS 3.1 When I try to generate a syslog report this shows me nothing. I locate SyslogCollector.log file and I see sometnig wrong.

View 4 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved