Cisco ISR 4000 Family Routers Administrator Guidance
Requirement
Auditable Events
Additional
Audit Record
Contents
Jun 20 07:42:26.823: ISAKMP:(0):Input
=
IKE_MM_EXCH
Jun 20 07:42:26.823: ISAKMP:(0):Old
State = IKE_READY New State
= IKE_R_MM1 ...
Jun 20 07:42:26.823: ISAKMP:(0):found
peer pre-shared key matching 100.1.1.5
Jun 20 07:42:26.823: ISAKMP:(0): local
preshared key found
Jun
20
Scanning profiles for xauth ...
Jun
ISAKMP:(0):Checking
transform 1 against priority 1 policy
Jun
20
encryption AES-CBC
Jun
20
keylength of 128
Jun 20 07:42:26.827: ISAKMP:
SHA
Jun
20
default group 14
Jun 20 07:42:26.827: ISAKMP:
pre-share...
Jun 20 07:42:26.843: ISAKMP (0):
received packet from 100.1.1.5 dport 500
sport 500 Global (R) MM_SA_SETUP
Jun 20 07:42:26.843: ISAKMP:(0):Input
=
IKE_MM_EXCH
Jun 20 07:42:26.843: ISAKMP:(0):Old
State = IKE_R_MM2
IKE_R_MM3
Jun 20 07:42:26.843: ISAKMP:(0):
processing KE payload. message ID = 0
Jun 20 07:42:27.055: ISAKMP:(0):
processing NONCE payload. message ID
= 0
Jun 20 07:42:27.059: ISAKMP:(0):found
peer pre-shared key matching 100.1.1.5
Sample Record
IKE_MESG_FROM_PEER,
07:42:26.823:
ISAKMP
20
07:42:26.823:
ISAKMP
07:42:26.827:
ISAKMP:
07:42:26.827:
ISAKMP:
hash
07:42:26.827:
ISAKMP:
auth
IKE_MESG_FROM_PEER,
New State =
Page 46 of 66
: