Administrative Access Logging

When a user tries to log onto the Web Management Console web administration pages, one of the following log messages appears:

Jan 30 03:00:18 2000 boa: Authentication successful for root from 10.0.0.2

Jan 30 03:00:14 2000 boa: Authentication attempt failed for root from 10.0.0.2

This message shows the date/time, whether the authentication succeeded or failed, the user attempting authentication (in this case root) and the IP address from which the attempt was made.

Telnet (Command Line Interface) login attempts appear as:

Jan 30 03:18:37 2000 login: Authentication attempt failed for root from 10.0.0.2

Jan 30 03:18:40 2000 login: Authentication successful for root from 10.0.0.2

Once again, showing the same information as a web login attempt.

Boot Log Messages

The CyberGuard SG appliance’s startup boot time messages are identified by log messages similar to the following:

klogd: Linux version 2.4.20-uc0 (jamma@daniel) (gcc version 3.0.4) #4 Mon Feb 3 15:17:50 EST 2003

This also shows the version of the operating system (linux), and the build date and time.

183

Appendix C – System Log

Page 187
Image 187
SnapGear 2.0.1 user manual Administrative Access Logging, Boot Log Messages, Appendix C System Log