Cisco PIX/ASA Template

Tested Cisco PIX/ASA Versions

This software has been tested on the following AIX versions:

  • ASA OS 8.1

Cisco PIX/ASA Controls

Action

Subaction

Condition

Description

Successful Login

Interactive Login

EventID=605005

This message appears when a user is authenticated successfully and a management session starts.

Successful Login

Successful AAA Login

EventID=113008

The AAA transaction for a user associated with an IPSec or WebVPN connection was completed successfully. The user is the username associated with the connection.

Successful Login

Successful AAA Login

EventID=113012

The user associated with a IPSec or WebVPN connection has been successfully authenticated to the local user database. user is the username associated with the connection.

Successful Login

Successful VPN Login

EventID=713052

This message indicates that the remote access user was authenticated.

Successful Login

Successful VPN Login

EventID=716001

The WebVPN session has started for the user in this group at the specified IP address. When the user logs in via the WebVPN login page, the WebVPN session starts.

Successful Login

Successful VPN Login

EventID=716055

The WebVPN user has been successfully authenticated to the SSO server.

Successful Login

Successful BVPN Login

EventID=719022

This message appears when the username is authenticated by the AAA server. The vpnuser is the WebVPN username.

Successful Login

Succesful ASDM Login

EventID=606001 | 606003

This message indicates that an administrator has been authenticated successfully and a ASDM session was started. | An ASDM logging connection is started by a remote management client.

Logon Failure

Interactive Login Failure

EventID=605004

This message appears after an incorrect login attempt or a failed login to the security appliance. For all logins, three attempts are allowed per session, and the session is terminated after three incorrect attempts. For SSH and TELNET logins, this message is generated after the third failed attempt or if the TCP session is terminated after one or more failed attempts. For other types of management sessions, this message is generated after every failed attempt.

Logon Failure

Interactive Login Failure

EventID=315011

This message appears after an SSH session completes. If a user enters quit or exit, the terminated normally message displays. If the session disconnected for another reason, the text describes the reason.

Logon Failure

AAA Logo Failure

EventID=113015

A request for authentication to the local user database for a user associated with an IPSec or WebVPN connection has been rejected. Details of why the request was rejected are provided in the reason field. user is the username associated with the connection.

Logon Failure

AAA Logon Failure

EventID=113005

This is an indication that either an authentication or authorization request for a user associated with an IPSec or WebVPN connection has been rejected. Details of why the request was rejected are provided in the reason field. server_IP_address is the IP address of the relevant AAA server. user is the user name associated with the connection. aaa_operation is either authentication or authorization.

Logon Failure

AAA Logon Failure

EventID=113013

The AAA transaction for a user associated with an IPSec or WebVPN connection has failed due to an error or has been rejected due to a policy violation. Details are provided in the reason field. user is the username associated with the connection.

Logon Failure

Logon Failure

EventID=113017

This is an indication that the AAA transaction for a user associated with an IPSec or WebVPN connection has failed due to an error or rejected due to a policy violation. Details are provided in the reason field. This event only appears when the AAA transaction is with the local user database rather than with an external AAA server. user is the username associated with the connection.

Logon Failure

Logon Failure

EventID=109006

This is a AAA message. This message is displayed if the specified authentication request fails, possibly because of an incorrect password.

Logon Failure

Logon Failure

EventID=109008

This is a AAA message. This message is displayed if a user is not authorized to access the specified address, possibly because of an incorrect password.

Logon Failure

Logon Failure

EventID=109031

This message is displayed when a user tries to authenticate to an NT Auth domain that was configured for guest account access and the username is not a valid username on the NT server. The connection is denied.

Logon Failure

AAA Logon Failure

EventID-113016

The AAA transaction for a user associated with an IPSec or WebVPN connection has failed due to an error or rejected due to a policy violation. Details are provided in the reason field. server_IP_address is the IP address of the relevant AAA server. user is the username associated with the connection.

Logon Failure

AAA Logon Failure

EventID=308001

This is a security appliance management message. This message is displayed after the specified number of times a user incorrectly types the password to enter privileged mode. The maximum is three attempts.

Logon Failure

Logon Failure

EventID=611102

User authentication failed when attempting to access the security appliance.

Logon Failure

Logon Failure

EventID=713161 | 713162

The security appliance server has sent the security appliance a message indicating that this user must be restricted. There are several reasons for this including security appliance software upgrades, changes in permissions, and so on. The security appliance server will transition the user back into full access mode as soon as the operation has been completed. | This message indicates that the security appliance server has rejected this user.

Logon Failure

Logon Failure

EventID=713166 | 713167

This message indicates that the hardware client has failed extended authentication. This is most likely a username/password problem or authentication server issue. | This message indicates that the remote user has failed to extend authentication. This is most likely a username or password problem or authentication server issue.

Logon Failure

Logon Failure

EventID=713185

The client returned an invalid length username and the tunnel was torn down.

Logon Failure

Logon Failure

EventID=713198

This event will contain a reason string

Logon Failure

Logon Failure

EventID=716037

A user attempted to log in to a server via the CIFS protocol but was not successful.

Logon Failure

VPN Logon Failure

EventID=716039

Before a WebVPN session starts, the user must be authenticated successfully by a local or remote server (for example, RADIUS or TACACS+). In this case, the user credentials (user name and password) either did not match or the user does not have permission to start a WebVPN session.

Logon Failure

Logon Failure

EventID=716040

A user was unable to log in to WebVPN because the system is in the process of rebooting.

Logon Failure

Logon Failure

EventID=716056

The WebVPN user failed to authenticate to the SSO server.

Logon Failure

VPN Logon Failure

EventID=719023

This message appears when the username is denied by the AAA server. The session will be aborted. The user is not allowed to access the e-mail account. The vpnuser is the WebVPN username.

Lock

User Lock

EventID=113006

A locally configured user is being locked out. This happens when a configured number of consecutive authentication failures have occurred for this user and indicates that all future authentication attempts by this user will be rejected until an administrator unlocks the user using the clear aaa local user lockout command. user is the user that is now locked and number is the consecutive failure threshold configured with the aaa local authentication attempts max-fail command.

Unlock

User Unlock

EventID=113007

A locally configured user that was locked out after exceeding the maximum number of consecutive authentication failures set by the aaa local authentication attempts max-fail command has been unlocked by the indicated administrator.

Logoff

Logoff

EventID=606002

This message indicates that a ASDM session ended.

Logoff

Logoff

EventID=606004

 

User Statement

Command Execution

EventID=111008

The user entered any command, with the exception of a show command.

Configuration Rule Modification

Configuration Rule Modification

EventID=111001

This message is displayed when you enter the write command to store your configuration on a device (either floppy, Flash memory, TFTP, the failover standby unit, or the console terminal). The IP_address indicates whether the login was made at the console port or with a Telnet connection.

Configuration Rule Modification

Configuration Rule Modification

EventID=111003

This is a management message. This message is displayed when you erase the contents of Flash memory by entering the write erase command at the console. The IP_address value indicates whether the login was made at the console port or through a Telnet connection.

Configuration Rule Modification

Configuration Rule Modification

EventID=111007

This message is displayed when you enter the reload or configure command to read in a configuration. The device text can be floppy, memory, net, standby, or terminal. The IP_address value indicates whether the login was made at the console port or through a Telnet connection.

Configuration Rule Modification

Configuration Rule Modification

EventID=112001

This message is displayed when a request to clear the module configuration is completed. The source file and line number are identified.

Configuration Rule Modification

Configuration Rule Modification

EventID=113003

The group policy that is associated with the tunnel-group is being overridden with a user specific policy, policy_name. The policy_name is specified using the username command when LOCAL authentication is configured or is returned in the RADIUS CLASS attribute when RADIUS authentication is configured.

Configuration Rule Modification

Configuration Rule Modification

EventID=305009

An address translation slot was created. The slot translates the source address from the local side to the global side. In reverse, the slot translates the destination address from the global side to the local side.

Configuration Rule Modification

Configuration Rule Modification

EventID=305010

The address translation slot was deleted.