Cisco PIX/ASA Template
Tested Cisco PIX/ASA Versions
This software has been tested on the following AIX versions:
- ASA OS 8.1
Cisco PIX/ASA Controls
Action |
Subaction |
Condition |
Description |
Successful Login |
Interactive Login |
EventID=605005 |
This message appears when a user is authenticated successfully and a management session starts. |
Successful Login |
Successful AAA Login |
EventID=113008 |
The AAA transaction for a user associated with an IPSec or WebVPN connection was completed successfully. The user is the username associated with the connection. |
Successful Login |
Successful AAA Login |
EventID=113012 |
The user associated with a IPSec or WebVPN connection has been successfully authenticated to the local user database. user is the username associated with the connection. |
Successful Login |
Successful VPN Login |
EventID=713052 |
This message indicates that the remote access user was authenticated. |
Successful Login |
Successful VPN Login |
EventID=716001 |
The WebVPN session has started for the user in this group at the specified IP address. When the user logs in via the WebVPN login page, the WebVPN session starts. |
Successful Login |
Successful VPN Login |
EventID=716055 |
The WebVPN user has been successfully authenticated to the SSO server. |
Successful Login |
Successful BVPN Login |
EventID=719022 |
This message appears when the username is authenticated by the AAA server. The vpnuser is the WebVPN username. |
Successful Login |
Succesful ASDM Login |
EventID=606001 | 606003 |
This message indicates that an administrator has been authenticated successfully and a ASDM session was started. | An ASDM logging connection is started by a remote management client. |
Logon Failure |
Interactive Login Failure |
EventID=605004 |
This message appears after an incorrect login attempt or a failed login to the security appliance. For all logins, three attempts are allowed per session, and the session is terminated after three incorrect attempts. For SSH and TELNET logins, this message is generated after the third failed attempt or if the TCP session is terminated after one or more failed attempts. For other types of management sessions, this message is generated after every failed attempt. |
Logon Failure |
Interactive Login Failure |
EventID=315011 |
This message appears after an SSH session completes. If a user enters quit or exit, the terminated normally message displays. If the session disconnected for another reason, the text describes the reason. |
Logon Failure |
AAA Logo Failure |
EventID=113015 |
A request for authentication to the local user database for a user associated with an IPSec or WebVPN connection has been rejected. Details of why the request was rejected are provided in the reason field. user is the username associated with the connection. |
Logon Failure |
AAA Logon Failure |
EventID=113005 |
This is an indication that either an authentication or authorization request for a user associated with an IPSec or WebVPN connection has been rejected. Details of why the request was rejected are provided in the reason field. server_IP_address is the IP address of the relevant AAA server. user is the user name associated with the connection. aaa_operation is either authentication or authorization. |
Logon Failure |
AAA Logon Failure |
EventID=113013 |
The AAA transaction for a user associated with an IPSec or WebVPN connection has failed due to an error or has been rejected due to a policy violation. Details are provided in the reason field. user is the username associated with the connection. |
Logon Failure |
Logon Failure |
EventID=113017 |
This is an indication that the AAA transaction for a user associated with an IPSec or WebVPN connection has failed due to an error or rejected due to a policy violation. Details are provided in the reason field. This event only appears when the AAA transaction is with the local user database rather than with an external AAA server. user is the username associated with the connection. |
Logon Failure |
Logon Failure |
EventID=109006 |
This is a AAA message. This message is displayed if the specified authentication request fails, possibly because of an incorrect password. |
Logon Failure |
Logon Failure |
EventID=109008 |
This is a AAA message. This message is displayed if a user is not authorized to access the specified address, possibly because of an incorrect password. |
Logon Failure |
Logon Failure |
EventID=109031 |
This message is displayed when a user tries to authenticate to an NT Auth domain that was configured for guest account access and the username is not a valid username on the NT server. The connection is denied. |
Logon Failure |
AAA Logon Failure |
EventID-113016 |
The AAA transaction for a user associated with an IPSec or WebVPN connection has failed due to an error or rejected due to a policy violation. Details are provided in the reason field. server_IP_address is the IP address of the relevant AAA server. user is the username associated with the connection. |
Logon Failure |
AAA Logon Failure |
EventID=308001 |
This is a security appliance management message. This message is displayed after the specified number of times a user incorrectly types the password to enter privileged mode. The maximum is three attempts. |
Logon Failure |
Logon Failure |
EventID=611102 |
User authentication failed when attempting to access the security appliance. |
Logon Failure |
Logon Failure |
EventID=713161 | 713162 |
The security appliance server has sent the security appliance a message indicating that this user must be restricted. There are several reasons for this including security appliance software upgrades, changes in permissions, and so on. The security appliance server will transition the user back into full access mode as soon as the operation has been completed. | This message indicates that the security appliance server has rejected this user. |
Logon Failure |
Logon Failure |
EventID=713166 | 713167 |
This message indicates that the hardware client has failed extended authentication. This is most likely a username/password problem or authentication server issue. | This message indicates that the remote user has failed to extend authentication. This is most likely a username or password problem or authentication server issue. |
Logon Failure |
Logon Failure |
EventID=713185 |
The client returned an invalid length username and the tunnel was torn down. |
Logon Failure |
Logon Failure |
EventID=713198 |
This event will contain a reason string |
Logon Failure |
Logon Failure |
EventID=716037 |
A user attempted to log in to a server via the CIFS protocol but was not successful. |
Logon Failure |
VPN Logon Failure |
EventID=716039 |
Before a WebVPN session starts, the user must be authenticated successfully by a local or remote server (for example, RADIUS or TACACS+). In this case, the user credentials (user name and password) either did not match or the user does not have permission to start a WebVPN session. |
Logon Failure |
Logon Failure |
EventID=716040 |
A user was unable to log in to WebVPN because the system is in the process of rebooting. |
Logon Failure |
Logon Failure |
EventID=716056 |
The WebVPN user failed to authenticate to the SSO server. |
Logon Failure |
VPN Logon Failure |
EventID=719023 |
This message appears when the username is denied by the AAA server. The session will be aborted. The user is not allowed to access the e-mail account. The vpnuser is the WebVPN username. |
Lock |
User Lock |
EventID=113006 |
A locally configured user is being locked out. This happens when a configured number of consecutive authentication failures have occurred for this user and indicates that all future authentication attempts by this user will be rejected until an administrator unlocks the user using the clear aaa local user lockout command. user is the user that is now locked and number is the consecutive failure threshold configured with the aaa local authentication attempts max-fail command. |
Unlock |
User Unlock |
EventID=113007 |
A locally configured user that was locked out after exceeding the maximum number of consecutive authentication failures set by the aaa local authentication attempts max-fail command has been unlocked by the indicated administrator. |
Logoff |
Logoff |
EventID=606002 |
This message indicates that a ASDM session ended. |
Logoff |
Logoff |
EventID=606004 |
|
User Statement |
Command Execution |
EventID=111008 |
The user entered any command, with the exception of a show command. |
Configuration Rule Modification |
Configuration Rule Modification |
EventID=111001 |
This message is displayed when you enter the write command to store your configuration on a device (either floppy, Flash memory, TFTP, the failover standby unit, or the console terminal). The IP_address indicates whether the login was made at the console port or with a Telnet connection. |
Configuration Rule Modification |
Configuration Rule Modification |
EventID=111003 |
This is a management message. This message is displayed when you erase the contents of Flash memory by entering the write erase command at the console. The IP_address value indicates whether the login was made at the console port or through a Telnet connection. |
Configuration Rule Modification |
Configuration Rule Modification |
EventID=111007 |
This message is displayed when you enter the reload or configure command to read in a configuration. The device text can be floppy, memory, net, standby, or terminal. The IP_address value indicates whether the login was made at the console port or through a Telnet connection. |
Configuration Rule Modification |
Configuration Rule Modification |
EventID=112001 |
This message is displayed when a request to clear the module configuration is completed. The source file and line number are identified. |
Configuration Rule Modification |
Configuration Rule Modification |
EventID=113003 |
The group policy that is associated with the tunnel-group is being overridden with a user specific policy, policy_name. The policy_name is specified using the username command when LOCAL authentication is configured or is returned in the RADIUS CLASS attribute when RADIUS authentication is configured. |
Configuration Rule Modification |
Configuration Rule Modification |
EventID=305009 |
An address translation slot was created. The slot translates the source address from the local side to the global side. In reverse, the slot translates the destination address from the global side to the local side. |
Configuration Rule Modification |
Configuration Rule Modification |
EventID=305010 |
The address translation slot was deleted. |