Event Logging Overview

The evaluated configuration requires the auditing of configuration changes through the system log.

In addition, Junos OS can:

  • Send automated responses to audit events (syslog entry creation).

  • Allow authorized managers to examine audit logs.

  • Send audit files to external servers.

  • Allow authorized managers to return the system to a known state.

The logging for the evaluated configuration must capture the events. The logging events are listed below:

Table 1 shows sample for syslog auditing for NDcPPv3.0e:

Table 1: Auditable Events
Requirement Auditable Events Additional Audit Record Contents Audit Records
FAU_GEN.1 None None
  • Start-up and shut-down of the audit functions;

Note: There is no manual startup/shutdown of the local audit function, which is tied to startup/shutdown of the TOE itself, logs for which implicitly indicate the audit function stopping and starting as well.

TOE Shutdown:

<45>1 2025-07-04T23:12:32.753Z MX480_TOE eventd 20463 SYSTEM_SHUTDOWN [junos@2636.1.1.1.2.25 type="shutdown" username="admin" time="Fri Jul 4 23:08:54 2025" message="no message"] System shutdown by admin at Fri Jul 4 23:08:54 2025: no message

TOE Startup:

<45>1 2025-07-04T23:12:32.754Z MX480_TOE eventd 20463 SYSTEM_OPERATIONAL - System is operational

  • All auditable events for the not specified level of audit;
  • All administrative actions comprising:
  • Administrative login and logout (name of Administrator account shall be logged if individual accounts are required for Administrators).

Login:

<38>1 2025-07-09T12:06:43.690Z MX480_TOE sshd 23064 - - Accepted keyboard-interactive/pam for acumensec from 10.1.5.84 port 35624 ssh2

<190>1 2025-07-09T12:06:43.780Z MX480_TOE mgd 23070 UI_AUTH_EVENT [junos@2636.1.1.1.2.25 username="acumensec" authentication-level="j-security-admin"] Authenticated user 'acumensec' assigned to class 'j-security-admin'

<190>1 2025-07-09T12:06:43.780Z MX480_TOE mgd 23070 UI_LOGIN_EVENT [junos@2636.1.1.1.2.25 username="acumensec" class-name="j-security-admin" local-peer="" pid="23070" ssh-connection="10.1.5.84 35624 10.1.2.158 22" client-mode="cli"] User 'acumensec' login, class 'j-security-admin' [23070], ssh-connection '10.1.5.84 35624 10.1.2.158 22', client-mode 'cli'

Logout

<38>1 2025-07-09T12:08:55.986Z MX480_TOE sshd 23068 - - Received disconnect from 10.1.5.84 port 35624:11: disconnected by user

<38>1 2025-07-09T12:08:55.986Z MX480_TOE sshd 23068 - - Disconnected from user acumensec 10.1.5.84 port 35624

  • Changes to TSF data related to configuration changes (in addition to the information that a change occurred it shall be logged what has been changed).

<182>1 2025-07-09T11:11:54.326Z MX480_TOE mgd 22519 UI_CFG_AUDIT_SET [junos@2636.1.1.1.2.25 username="admin" action="set" pathname="[system syslog file audit_file any\]" delimiter="" data="unconfigured" value="any"] User 'admin' set: [system syslog file audit_file any] unconfigured -- "any"

<190>1 2025-07-09T11:11:54.326Z MX480_TOE mgd 22519 UI_CMDLINE_READ_LINE [junos@2636.1.1.1.2.25 username="admin" command="set system syslog file audit_file any any "] User 'admin', command 'set system syslog file audit_file any any '

  • Generating/import of, changing, or deleting of cryptographic keys (in addition to the action itself a unique key name or key reference shall be logged).

Import of cryptographic keys (SSH):

<182>1 2025-08-12T10:54:36.309Z MX480_TOE mgd 21496 UI_CFG_AUDIT_OTHER [junos@2636.1.1.1.2.25 username="admin" action="set" pathname="[system login user cctester authentication ssh-rsa /* SECRET-DATA */\]" delimiter="" value=""] User 'admin' set: [system login user cctester authentication ssh-rsa /* SECRET-DATA */]

<190>1 2025-08-12T10:54:36.309Z MX480_TOE mgd 21496 UI_CMDLINE_READ_LINE [junos@2636.1.1.1.2.25 username="admin" command="set system login user cctester authentication ssh-rsa /* SECRET-DATA */ "] User 'admin', command 'set system login user cctester authentication ssh-rsa /* SECRET-DATA */ '

Deletion of cryptographic keys (SSH):

<190>1 2025-08-12T10:57:13.866Z MX480_TOE mgd 21496 UI_CMDLINE_READ_LINE [junos@2636.1.1.1.2.25 username="admin" command="delete system login user cctester authentication ssh-rsa /* SECRET-DATA */ "] User 'admin', command 'delete system login user cctester authentication ssh-rsa /* SECRET-DATA */ '

<182>1 2025-08-12T10:57:13.866Z MX480_TOE mgd 21496 UI_CFG_AUDIT_OTHER [junos@2636.1.1.1.2.25 username="admin" action="delete" pathname="[system login user cctester authentication ssh-rsa /* SECRET-DATA */\]" delimiter="" value=""] User 'admin' delete: [system login user cctester authentication ssh-rsa /* SECRET-DATA */]

  • [Resetting passwords (name of related Administrator account shall be logged)];

**NOTE: The logs mention data=”unconfigured” as the old value even when resetting an existing password to mask the sensitive information.

<182>1 2025-07-09T12:39:20.230Z MX480_TOE mgd 22148 UI_CFG_AUDIT_SET [junos@2636.1.1.1.2.25 username="admin" action="set" pathname="[system login user cctester authentication\]" delimiter="" data="unconfigured" value="plain-text-password"] User 'admin' set: [system login user cctester authentication] unconfigured -- "plain-text-password"

<190>1 2025-07-09T12:39:32.340Z MX480_TOE mgd 22148 UI_CMDLINE_READ_LINE [junos@2636.1.1.1.2.25 username="admin" command="set system login user cctester authentication plain-text-password "] User 'admin', command 'set system login user cctester authentication plain-text-password '

FAU_GEN.2 None None
FAU_STG_EXT.1 Configuration of local audit settings. Identity of account making changes to the audit configuration.

Configuration of local audit settings.

<182>1 2025-07-09T11:11:54.326Z MX480_TOE mgd 22519 UI_CFG_AUDIT_SET [junos@2636.1.1.1.2.25 username="admin" action="set" pathname="[system syslog file audit_file any\]" delimiter="" data="unconfigured" value="any"] User 'admin' set: [system syslog file audit_file any] unconfigured -- "any"

<190>1 2025-07-09T11:11:54.326Z MX480_TOE mgd 22519 UI_CMDLINE_READ_LINE [junos@2636.1.1.1.2.25 username="admin" command="set system syslog file audit_file any any "] User 'admin', command 'set system syslog file audit_file any any '

FCS_CKM.1 None None
FCS_CKM.2 None None
FCS_CKM.4 None None
FCS_COP.1/DataEncryption None None
FCS_COP.1/SigGen None None
FCS_COP.1/Hash None None
FCS_COP.1/KeyedHash None None
FCS_MACSEC_EXT.1 Session establishment Secure Channel Identifier (SCI)

<30>1 2025-09-17T14:19:21.580Z MX240 secure-dot1xd 23083 DOT1XD_MKA_SECURE_CHANNEL_CREATED [junos@2636.1.1.1.2.29 mac-address="7c:25:86:ab:28:40" interface-name="ge-0/0/0"] Macsec receive secure channel created for 7c:25:86:ab:28:40 on interface ge-0/0/0

<28>1 2025-09-17T14:19:31.043Z MX240 secure-dot1xd 23083 DOT1XD_MACSEC_SC_CAK_ACTIVATED [junos@2636.1.1.1.2.29 interface-name="ge-0/0/0" sc-id0="5800BB0A680C0001" sc-id1="7C2586AB28400001" pre-shared-key="1234567890"] ifd: ge-0/0/0 sci-out:5800BB0A680C0001 sci-in:7C2586AB28400001 ckn: 1234567890

FCS_MACSEC_EXT.3 Creation and update of SAK Creation and update times

Creation of SAK:

<30>1 2025-10-14T11:24:42.053Z MX240 secure-dot1xd 21596 DOT1XD_MKA_SECURE_CHANNEL_CREATED [junos@2636.1.1.1.2.29 mac-address="7c:25:86:ab:28:40" interface-name="ge-0/0/0"] Macsec receive secure channel created for 7c:25:86:ab:28:40 on interface ge-0/0/0

Update of SAK:

<30>1 2025-09-29T13:26:29.994Z MX240 secure-dot1xd 23083 DOT1XD_MKA_SAK_REKEY_EVENT [junos@2636.1.1.1.2.29 interface-name="ge-0/0/0"] MKA sak-rekey event started for the interface: ge-0/0/0

<30>1 2025-09-29T13:26:29.994Z MX240 secure-dot1xd 23083 DOT1XD_MKA_SA_KEY_ROLLOVER [junos@2636.1.1.1.2.29 interface-name="ge-0/0/0"] Macsec secure association key rolled over on interface ge-0/0/0

FCS_MACSEC_EXT.4 Creation of CA Connectivity Association Key Names (CKNs)

<30>1 2025-10-14T11:24:42.053Z MX240 secure-dot1xd 21596 DOT1XD_MKA_SECURE_CHANNEL_CREATED [junos@2636.1.1.1.2.29 mac-address="7c:25:86:ab:28:40" interface-name="ge-0/0/0"] Macsec receive secure channel created for 7c:25:86:ab:28:40 on interface ge-0/0/0

<30>1 2025-10-14T11:24:42.601Z MX240 secure-dot1xd 21596 DOT1XD_MKA_SECURE_ASSOCIATION_ESTABLISHED [junos@2636.1.1.1.2.29 sequence-number="0" interface-name="ge-0/0/0"] Macsec secure association established with an:0 on interface ge-0/0/0

<28>1 2025-10-14T11:24:42.601Z MX240 secure-dot1xd 21596 DOT1XD_MACSEC_SC_PRIMARY_CAK_IN_USE [junos@2636.1.1.1.2.29 interface-name="ge-0/0/0" pre-shared-key="ABCDEF0123456789ABCDEF0123456789"] ifd: ge-0/0/0 primary ckn: ABCDEF0123456789ABCDEF0123456789 is in-use

<28>1 2025-10-14T11:24:48.281Z MX240 secure-dot1xd 21596 DOT1XD_MACSEC_SC_CAK_ACTIVATED [junos@2636.1.1.1.2.29 interface-name="ge-0/0/0" sc-id0="5800BB0A680C0001" sc-id1="7C2586AB28400001" pre-shared-key="ABCDEF0123456789ABCDEF0123456789"] ifd: ge-0/0/0 sci-out:5800BB0A680C0001 sci-in:7C2586AB28400001 ckn: ABCDEF0123456789ABCDEF0123456789

FCS_RBG_EXT.1 None None
FCS_SSH_EXT.1 Failure to establish SSH connection Reason for failure and [Non-TOE endpoint of attempted connection (IP Address)]

Failure to establish SSH connection

Unsupported cipher

<38>1 2025-08-12T11:53:11.090Z MX480_TOE sshd 30530 - - Unable to negotiate with 10.1.2.65 port 49874: no matching cipher found. Their offer: aes192-ctr [preauth]

Unsupported hashing algorithm

<38>1 2025-08-12T12:03:26.860Z MX480_TOE sshd 24607 - - Unable to negotiate with 10.1.2.65 port 55976: no matching MAC found. Their offer: hmac-md5 [preauth]

Unsupported key exchange method

<38>1 2025-08-12T12:05:48.942Z MX480_TOE sshd 24672 - - Unable to negotiate with 10.1.2.65 port 59712: no matching key exchange method found. Their offer: diffie-hellman-group14-sha1,ext-info-c,kex-strict-c-v00@openssh.com [preauth]

Establishment of SSH connection [Non-TOE endpoint of attempted connection (IP Address)]

Establishment of SSH connection

<38>1 2025-07-09T12:06:43.690Z MX480_TOE sshd 23064 - - Accepted keyboard-interactive/pam for acumensec from 10.1.5.84 port 35624 ssh2

<190>1 2025-07-09T12:06:43.780Z MX480_TOE mgd 23070 UI_AUTH_EVENT [junos@2636.1.1.1.2.25 username="acumensec" authentication-level="j-security-admin"] Authenticated user 'acumensec' assigned to class 'j-security-admin'

<190>1 2025-07-09T12:06:43.780Z MX480_TOE mgd 23070 UI_LOGIN_EVENT [junos@2636.1.1.1.2.25 username="acumensec" class-name="j-security-admin" local-peer="" pid="23070" ssh-connection="10.1.5.84 35624 10.1.2.158 22" client-mode="cli"] User 'acumensec' login, class 'j-security-admin' [23070], ssh-connection '10.1.5.84 35624 10.1.2.158 22', client-mode 'cli'

Termination of SSH connection session [Non-TOE endpoint of attempted connection (IP Address)]

Termination of SSH connection session

<38>1 2025-07-09T12:08:55.986Z MX480_TOE sshd 23068 - - Received disconnect from 10.1.5.84 port 35624:11: disconnected by user

<38>1 2025-07-09T12:08:55.986Z MX480_TOE sshd 23068 - - Disconnected from user acumensec 10.1.5.84 port 35624

Dropping of packet(s) outside defined size limits [Packet Size]

<38>1 2025-09-30T11:01:46.335Z MX480_TOE sshd 65440 - - Accepted password for admin from 10.1.5.84 port 44272 ssh2

<38>1 2025-09-30T11:01:46.339Z MX480_TOE sshd 65442 - - Potential replay attack detected on SSH connection initiated from 10.1.5.84:44272

<37>1 2025-09-30T11:01:46.339Z MX480_TOE sshd - SSH_MSG_REPLAY_DETECT [junos@2636.1.1.1.2.25 source-address="10.1.5.84" source-port="44272"] Potential replay attack detected on SSH connection initiated from 10.1.5.84:44272

<38>1 2025-09-30T11:01:46.340Z MX480_TOE sshd 65442 - - Bad packet length 262145.

<28>1 2025-09-30T11:01:46.341Z MX480_TOE inetd 21046 - - /usr/sbin/sshd[65440]: exited, status 255

FCS_SSHS_EXT.1 No events specified None None
FCS_NTP_EXT.1
  • Configuration of a new time server
  • Removal of configured time server
Identity of new/removed time server
  • Configuration of a new time server

<182>1 2025-07-24T10:41:28.618Z MX480_TOE mgd 21755 UI_CFG_AUDIT_OTHER [junos@2636.1.1.1.2.25 username="admin" action="set" pathname="[system ntp server 10.1.5.84\]" delimiter="" value=""] User 'admin' set: [system ntp server 10.1.5.84]

<182>1 2025-07-24T10:41:28.618Z MX480_TOE mgd 21755 UI_CFG_AUDIT_SET_SECRET [junos@2636.1.1.1.2.25 username="admin" action="set" pathname="[system ntp server 10.1.5.84 key\]"] User 'admin' set: [system ntp server 10.1.5.84 key]

<182>1 2025-07-24T10:41:28.618Z MX480_TOE mgd 21755 UI_CFG_AUDIT_SET [junos@2636.1.1.1.2.25 username="admin" action="set" pathname="[system ntp server 10.1.5.84 version\]" delimiter="" data="unconfigured" value="4"] User 'admin' set: [system ntp server 10.1.5.84 version] unconfigured -- "4"

<190>1 2025-07-24T10:41:28.618Z MX480_TOE mgd 21755 UI_CMDLINE_READ_LINE [junos@2636.1.1.1.2.25 username="admin" command="set system ntp server 10.1.5.84 key /* SECRET-DATA */ version 4 "] User 'admin', command 'set system ntp server 10.1.5.84 key /* SECRET-DATA */ version 4 '

  • Removal of configured time server

<190>1 2025-07-24T10:43:05.455Z MX480_TOE mgd 21755 UI_CMDLINE_READ_LINE [junos@2636.1.1.1.2.25 username="admin" command="delete system ntp server 10.1.5.84 "] User 'admin', command 'delete system ntp server 10.1.5.84 '

<182>1 2025-07-24T10:43:05.455Z MX480_TOE mgd 21755 UI_CFG_AUDIT_OTHER [junos@2636.1.1.1.2.25 username="admin" action="delete" pathname="[system ntp server 10.1.5.84\]" delimiter="" value=""] User 'admin' delete: [system ntp server 10.1.5.84]

FIA_UIA_EXT.1 All use of identification and authentication mechanism Origin of the attempt (e.g., IP address)

All use of identification and authentication mechanism

Local Successful Login

<37>1 2025-07-11T16:17:50.080Z MX480_TOE login 76412 - - Login attempt for user acumensec from host [unknown]

<38>1 2025-07-11T16:17:53.680Z MX480_TOE login 76412 LOGIN_INFORMATION [junos@2636.1.1.1.2.25 username="acumensec" hostname="[unknown\]" tty-name="ttyu0"] User acumensec logged in from host [unknown] on device ttyu0

<190>1 2025-07-11T16:17:53.726Z MX480_TOE mgd 76415 UI_AUTH_EVENT [junos@2636.1.1.1.2.25 username="acumensec" authentication-level="j-security-admin"] Authenticated user 'acumensec' assigned to class 'j-security-admin'

<190>1 2025-07-11T16:17:53.726Z MX480_TOE mgd 76415 UI_LOGIN_EVENT [junos@2636.1.1.1.2.25 username="acumensec" class-name="j-security-admin" local-peer="" pid="76415" ssh-connection="" client-mode="cli"] User 'acumensec' login, class 'j-security-admin' [76415], ssh-connection '', client-mode 'cli'

Local Unsuccessful Login

<37>1 2025-07-11T16:05:45.358Z MX480_TOE login 75983 - - Login attempt for user acumensec from host [unknown]

<35>1 2025-07-11T16:05:46.548Z MX480_TOE login 75983 PAM_UNIX_LOC_PASSWD_AUTH [junos@2636.1.1.1.2.25 username="acumensec" result="failed"] local password authentication of user 'acumensec' failed

<35>1 2025-07-11T16:05:46.549Z MX480_TOE login 75983 LOGIN_PAM_AUTHENTICATION_ERROR [junos@2636.1.1.1.2.25 username="acumensec"] Failed password for user acumensec

<37>1 2025-07-11T16:05:46.549Z MX480_TOE login 75983 LOGIN_FAILED [junos@2636.1.1.1.2.25 username="acumensec" source-address="ttyu0"] Login failed for user acumensec from host ttyu0

Remote Successful Password-Based Login

<38>1 2025-08-04T11:00:37.144Z MX480_TOE sshd 86747 - - Accepted password for acumensec from 10.1.5.84 port 36318 ssh2

<190>1 2025-08-04T11:00:37.235Z MX480_TOE mgd 86751 UI_AUTH_EVENT [junos@2636.1.1.1.2.25 username="acumensec" authentication-level="j-security-admin"] Authenticated user 'acumensec' assigned to class 'j-security-admin'

<190>1 2025-08-04T11:00:37.235Z MX480_TOE mgd 86751 UI_LOGIN_EVENT [junos@2636.1.1.1.2.25 username="acumensec" class-name="j-security-admin" local-peer="" pid="86751" ssh-connection="10.1.5.84 36318 10.1.2.158 22" client-mode="cli"] User 'acumensec' login, class 'j-security-admin' [86751], ssh-connection '10.1.5.84 36318 10.1.2.158 22', client-mode 'cli'

Remote Unsuccessful Password-Based Login

<35>1 2025-07-11T16:39:14.888Z MX480_TOE sshd - PAM_UNIX_LOC_PASSWD_AUTH [junos@2636.1.1.1.2.25 username="acumensec" result="failed"] local password authentication of user 'acumensec' failed

<15>1 2025-07-11T16:39:14.888Z MX480_TOE sshd - PAM_USER_LOCK_USER [junos@2636.1.1.1.2.25 event-function-name="pam_sm_authenticate" username="acumensec"] (pam_sm_authenticate): DEBUG: PAM_USER: acumensec

<15>1 2025-07-11T16:39:14.889Z MX480_TOE sshd - PAM_USER_LOCK_UPD_LOCK_ATTEMPTS [junos@2636.1.1.1.2.25 event-function-name="pam_sm_authenticate" username="acumensec" num-msgs-forward="1"] (pam_sm_authenticate): DEBUG: Updating lock-attempts of user: acumensec attempts: 1

<35>1 2025-07-11T16:39:14.889Z MX480_TOE sshd 77211 - - error: PAM: Authentication error for acumensec from 10.1.5.84

<37>1 2025-07-11T16:39:14.890Z MX480_TOE sshd - SSHD_LOGIN_FAILED [junos@2636.1.1.1.2.25 username="acumensec" source-address="10.1.5.84"] Login failed for user 'acumensec' from host '10.1.5.84'

Remote Successful Public Key-Based Login

<38>1 2025-07-14T20:06:49.571Z MX480_TOE sshd 40869 - - Accepted publickey for admin from 10.1.5.84 port 39202 ssh2: RSA SHA256:z1HjGXyPNrVziK39ieCsdzP99cDVXpZIMvPtuAiTrps

<190>1 2025-07-14T20:06:49.680Z MX480_TOE mgd 40873 UI_AUTH_EVENT [junos@2636.1.1.1.2.25 username="admin" authentication-level="j-security-admin"] Authenticated user 'admin' assigned to class 'j-security-admin'

<190>1 2025-07-14T20:06:49.680Z MX480_TOE mgd 40873 UI_LOGIN_EVENT [junos@2636.1.1.1.2.25 username="admin" class-name="j-security-admin" local-peer="" pid="40873" ssh-connection="10.1.5.84 39202 10.1.2.158 22" client-mode="cli"] User 'admin' login, class 'j-security-admin' [40873], ssh-connection '10.1.5.84 39202 10.1.2.158 22', client-mode 'cli'

Remote Unsuccessful Public Key-Based Login

<38>1 2025-09-04T09:44:20.435Z MX480_TOE sshd 93275 - - Connection closed by authenticating user tester 10.1.5.84 port 55022 [preauth]

<28>1 2025-09-04T09:44:20.436Z MX480_TOE inetd 20984 - - /usr/sbin/sshd[93275]: exited, status 255

FIA_AFL.1 Unsuccessful login attempts limit is met or exceeded Origin of the attempt (e.g., IP address)

Unsuccessful login attempts limit is met or exceeded

Aug 15 18:05:17 2025 MX480_TOE sshd[94713]: error: PAM: Authentication error for tester from 10.1.5.84

Aug 15 18:05:17 2025 MX480_TOE sshd: SSHD_LOGIN_FAILED: Login failed for user 'tester' from host '10.1.5.84'

Aug 15 18:05:18 2025 MX480_TOE sshd[94713]: error: PAM: Authentication error for tester from 10.1.5.84

Aug 15 18:05:18 2025 MX480_TOE sshd: SSHD_LOGIN_FAILED: Login failed for user 'tester' from host '10.1.5.84'

Aug 15 18:05:25 2025 MX480_TOE sshd: LIBJNX_LOGIN_ACCOUNT_LOCKED: Account for user 'tester' has been locked out from logins

Aug 15 18:05:25 2025 MX480_TOE sshd: PAM_USER_LOCK_LOGIN_REQUESTS_DENIED: Login requests from host '10.1.5.84' are denied

Aug 15 18:05:25 2025 MX480_TOE sshd[94713]: error: PAM: Authentication error for tester from 10.1.5.84

Aug 15 18:05:25 2025 MX480_TOE sshd: SSHD_LOGIN_FAILED: Login failed for user 'tester' from host '10.1.5.84'

Aug 15 18:05:40 2025 MX480_TOE sshd: SSHD_LOGIN_ATTEMPTS_THRESHOLD: Threshold for unsuccessful authentication attempts (3) reached by user 'tester'

Aug 15 18:05:40 2025 MX480_TOE sshd[94713]: Disconnecting authenticating user tester 10.1.5.84 port 48596: Too many password failures for tester [preauth]

Aug 15 18:05:40 2025 MX480_TOE sshd[94714]: Disconnecting authenticating user tester 10.1.5.84 port 48596: Too many password failures for tester

Aug 15 18:05:40 2025 MX480_TOE inetd[23345]: /usr/sbin/sshd[94713]: exited, status 255

FIA_PMG_EXT.1 None None
FIA_UAU.7 None None
FMT_MOF.1/ManualUpdate Any attempt to initiate a manual update None

Any attempt to initiate a manual update

<190>1 2025-08-11T05:41:24.812Z MX480_TOE mgd 49536 UI_CHILD_START [junos@2636.1.1.1.2.25 command="/usr/libexec/ui/package"] Starting child '/usr/libexec/ui/package'

<29>1 2025-08-11T05:41:24.814Z MX480_TOE mgd 49536 - - /usr/libexec/ui/package -X update /var/tmp/junos-vmhost-install-mx-x86-64-24.4R1.9.tgz

FMT_MOF.1/Functions None None
FMT_MOF.1/Services None None
FMT_MTD.1/CoreData None None
FMT_MTD.1/CryptoKeys None None
FMT_SMF.1 All management activities of TSF data. None

Ability to administer the TOE remotely

<38>1 2025-07-09T12:06:43.690Z MX480_TOE sshd 23064 - - Accepted keyboard-interactive/pam for acumensec from 10.1.5.84 port 35624 ssh2

<190>1 2025-07-09T12:06:43.780Z MX480_TOE mgd 23070 UI_AUTH_EVENT [junos@2636.1.1.1.2.25 username="acumensec" authentication-level="j-security-admin"] Authenticated user 'acumensec' assigned to class 'j-security-admin'

<190>1 2025-07-09T12:06:43.780Z MX480_TOE mgd 23070 UI_LOGIN_EVENT [junos@2636.1.1.1.2.25 username="acumensec" class-name="j-security-admin" local-peer="" pid="23070" ssh-connection="10.1.5.84 35624 10.1.2.158 22" client-mode="cli"] User 'acumensec' login, class 'j-security-admin' [23070], ssh-connection '10.1.5.84 35624 10.1.2.158 22', client-mode 'cli'

Ability to configure the access banner

<182>1 2025-08-04T05:48:50.806Z MX480_TOE mgd 69167 UI_CFG_AUDIT_SET [junos@2636.1.1.1.2.25 username="admin" action="set" pathname="[system login message\]" delimiter="" data="unconfigured" value="This is a LOGIN message for MX 480.\\nAuthorized users only !!!"] User 'admin' set: [system login message] unconfigured -- "This is a LOGIN message for MX 480.\nAuthorized users only !!!"

<190>1 2025-08-04T05:48:50.806Z MX480_TOE mgd 69167 UI_CMDLINE_READ_LINE [junos@2636.1.1.1.2.25 username="admin" command="set system login message \"This is a LOGIN messagefor MX 480.\\nAuthorized users only !!!\" "] User 'admin', command 'set system login message "This is a LOGIN message for MX 480.\nAuthorized users only !!!" '

Ability to configure the remote session inactivity time before session termination

<182>1 2025-08-04T10:35:29.803Z MX480_TOE mgd 71233 UI_CFG_AUDIT_SET [junos@2636.1.1.1.2.25 username="admin" action="set" pathname="[system login class security-admin idle-timeout\]" delimiter="" data="unconfigured" value="1"] User 'admin' set: [system login class security-admin idle-timeout] unconfigured -- "1"

<190>1 2025-08-04T10:35:29.804Z MX480_TOE mgd 71233 UI_CMDLINE_READ_LINE [junos@2636.1.1.1.2.25 username="admin" command="set system login class security-admin idle-timeout 1 "] User 'admin', command 'set system login class security-admin idle-timeout 1 '

Ability to update the TOE, and to verify the updates using digital signature capability prior to installing those updates

<190>1 2025-08-11T05:41:24.812Z MX480_TOE mgd 49536 UI_CHILD_START [junos@2636.1.1.1.2.25 command="/usr/libexec/ui/package"] Starting child '/usr/libexec/ui/package'

<29>1 2025-08-11T05:41:24.814Z MX480_TOE mgd 49536 - - /usr/libexec/ui/package -X update /var/tmp/junos-vmhost-install-mx-x86-64-24.4R1.9.tgz

<190>1 2025-08-11T05:48:16.808Z MX480_TOE mgd 49536 UI_CHILD_STATUS [junos@2636.1.1.1.2.25 command="/usr/libexec/ui/package" pid="71662" status-code="0"] Cleanup child '/usr/libexec/ui/package', PID 71662, status 0

<118>1 2025-08-11T05:57:17.200Z MX480_TOE kernel - - - Verified os-kernel-prd-x86-64-20241104 signed by PackageProductionECP256_2024 method ECDSA256+SHA256

<118>1 2025-08-11T05:57:17.200Z MX480_TOE kernel - - - Verified os-libs-15-x86-64-20241104 signed by PackageProductionECP256_2024 method ECDSA256+SHA256

<118>1 2025-08-11T05:57:17.200Z MX480_TOE kernel - - - Verified os-runtime-x86-64-20241104 signed by PackageProductionECP256_2024 method ECDSA256+SHA256

<118>1 2025-08-11T05:57:17.200Z MX480_TOE kernel - - - Verified os-package-20241014 signed by Package ProductionECP256_2024 method ECDSA256+SHA256

Ability to start and stop services

Starting services

<182>1 2025-10-09T09:32:27.377Z MX480_TOE mgd 12714 UI_CFG_AUDIT_OTHER [junos@2636.1.1.1.2.25 username="admin" action="set" pathname="[system services netconf ssh\]" delimiter="" value=""] User 'admin' set: [system services netconf ssh]

<190>1 2025-10-09T09:32:27.377Z MX480_TOE mgd 12714 UI_CMDLINE_READ_LINE [junos@2636.1.1.1.2.25 username="admin" command="set system services netconf ssh "] User 'admin', command 'set system services netconf ssh '

Stopping services

<190>1 2025-10-09T09:34:59.262Z MX480_TOE mgd 12714 UI_CMDLINE_READ_LINE [junos@2636.1.1.1.2.25 username="admin" command="delete system services netconf ssh "] User 'admin', command 'delete system services netconf ssh '

<182>1 2025-10-09T09:34:59.262Z MX480_TOE mgd 12714 UI_CFG_AUDIT_OTHER [junos@2636.1.1.1.2.25 username="admin" action="delete" pathname="[system services netconf ssh\]" delimiter="" value=""] User 'admin' delete: [system services netconf ssh]

Ability to configure local audit behaviour (e.g. changes to storage locations for audit; changes to behaviour when local audit storage space is full, changes to local audit storage size)

<182>1 2025-07-14T09:48:54.261Z MX480_TOE mgd 57387 UI_CFG_AUDIT_SET [junos@263 6.1.1.1.2.25 username="admin" action="set" pathname="[system syslog file syslog archive size\]" delimiter="\"" data="10m" value="11m"] User 'admin' set: [system syslog file syslog archive size] "10m -- "11m"

<190>1 2025-07-14T09:48:54.261Z MX480_TOE mgd 57387 UI_CMDLINE_READ_LINE [junos @2636.1.1.1.2.25 username="admin" command="set system syslog file syslog archiv e size 11m "] User 'admin', command 'set system syslog file syslog archive size 11m '

Ability to modify the behaviour of the transmission of audit data to an external IT entity

<182>1 2025-10-09T09:32:27.377Z MX480_TOE mgd 12714 UI_CFG_AUDIT_OTHER [junos@2636.1.1.1.2.25 username="admin" action="set" pathname="[system services netconf ssh\]" delimiter="" value=""] User 'admin' set: [system services netconf ssh]

<190>1 2025-10-09T09:32:27.377Z MX480_TOE mgd 12714 UI_CMDLINE_READ_LINE [junos@2636.1.1.1.2.25 username="admin" command="set system services netconf ssh "] User 'admin', command 'set system services netconf ssh '

Ability to manage the cryptographic keys

<182>1 2025-08-12T10:54:36.309Z MX480_TOE mgd 21496 UI_CFG_AUDIT_OTHER [junos@2636.1.1.1.2.25 username="admin" action="set" pathname="[system login user cctester authentication ssh-rsa /* SECRET-DATA */\]" delimiter="" value=""] User 'admin' set: [system login user cctester authentication ssh-rsa /* SECRET-DATA */]

<190>1 2025-08-12T10:54:36.309Z MX480_TOE mgd 21496 UI_CMDLINE_READ_LINE [junos@2636.1.1.1.2.25 username="admin" command="set system login user cctester authentication ssh-rsa /* SECRET-DATA */ "] User 'admin', command 'set system login user cctester authentication ssh-rsa /* SECRET-DATA */ '

Ability to configure thresholds for SSH rekeying

<182>1 2025-10-09T09:25:56.067Z MX480_TOE mgd 12714 UI_CFG_AUDIT_SET [junos@2636.1.1.1.2.25 username="admin" action="set" pathname="[system services ssh rekey time-limit\]" delimiter="" data="unconfigured" value="60"] User 'admin' set: [system services ssh rekey time-limit] unconfigured -- "60"

<190>1 2025-10-09T09:25:56.067Z MX480_TOE mgd 12714 UI_CMDLINE_READ_LINE [junos@2636.1.1.1.2.25 username="admin" command="set system services ssh rekey time-limit 60 "] User 'admin', command 'set system services ssh rekey time-limit 60 '

<182>1 2025-10-09T09:26:20.131Z MX480_TOE mgd 12714 UI_CFG_AUDIT_SET [junos@2636.1.1.1.2.25 username="admin" action="set" pathname="[system services ssh rekey data-limit\]" delimiter="" data="unconfigured" value="15m"] User 'admin' set: [system services ssh rekey data-limit] unconfigured -- "15m"

<190>1 2025-10-09T09:26:20.131Z MX480_TOE mgd 12714 UI_CMDLINE_READ_LINE [junos@2636.1.1.1.2.25 username="admin" command="set system services ssh rekey data-limit 15m "] User 'admin', command 'set system services ssh rekey data-limit 15m '

Ability to re-enable an Administrator account

<190>1 2025-10-09T09:20:21.480Z MX480_TOE mgd 12714 UI_CMDLINE_READ_LINE [junos@2636.1.1.1.2.25 username="admin" command="clear system login lockout user acumensec "] User 'admin', command 'clear system login lockout user acumensec '

<37>1 2025-10-09T09:20:21.481Z MX480_TOE mgd 12714 LIBJNX_LOGIN_ACCOUNT_UNLOCKED [junos@2636.1.1.1.2.25 username="acumensec"] Account for user 'acumensec' has been unlocked for logins

Ability to configure the local session inactivity time before session termination or locking

<182>1 2025-08-04T10:35:29.803Z MX480_TOE mgd 71233 UI_CFG_AUDIT_SET [junos@2636.1.1.1.2.25 username="admin" action="set" pathname="[system login class security-admin idle-timeout\]" delimiter="" data="unconfigured" value="1"] User 'admin' set: [system login class security-admin idle-timeout] unconfigured -- "1"

<190>1 2025-08-04T10:35:29.804Z MX480_TOE mgd 71233 UI_CMDLINE_READ_LINE [junos@2636.1.1.1.2.25 username="admin" command="set system login class security-admin idle-timeout 1 "] User 'admin', command 'set system login class security-admin idle-timeout 1 '

Ability to configure the authentication failure parameters for FIA_AFL.1

<182>1 2025-10-09T09:11:05.287Z MX480_TOE mgd 12714 UI_CFG_AUDIT_SET [junos@2636.1.1.1.2.25 username="admin" action="set" pathname="[system login retry-options tries-before-disconnect\]" delimiter="\"" data="3" value="3"] User 'admin' set: [system login retry-options tries-before-disconnect] "3 -- "3"

<190>1 2025-10-09T09:11:05.288Z MX480_TOE mgd 12714 UI_CMDLINE_READ_LINE [junos@2636.1.1.1.2.25 username="admin" command="set system login retry-options tries-before-disconnect 3 "] User 'admin', command 'set system login retry-options tries-before-disconnect 3 '

<182>1 2025-10-09T09:11:23.622Z MX480_TOE mgd 12714 UI_CFG_AUDIT_SET [junos@2636.1.1.1.2.25 username="admin" action="set" pathname="[system login retry-options lockout-period\]" delimiter="\"" data="5" value="5"] User 'admin' set: [system login retry-options lockout-period] "5 -- "5"

<190>1 2025-10-09T09:11:23.622Z MX480_TOE mgd 12714 UI_CMDLINE_READ_LINE [junos@2636.1.1.1.2.25 username="admin" command="set system login retry-options lockout-period 5 "] User 'admin', command 'set system login retry-options lockout-period 5 '

Ability to set the time which is used for time-stamps

<190>1 2025-08-06T06:59:31.596Z MX480_TOE mgd 87699 UI_CMDLINE_READ_LINE [junos@2636.1.1.1.2.25 username="admin" command="set date 202601010808.08 "] User 'admin', command 'set date 202601010808.08 '

<190>1 2025-08-06T06:59:31.598Z MX480_TOE mgd 87699 UI_CHILD_START [junos@2636.1.1.1.2.25 command="/bin/date"] Starting child '/bin/date'

<37>1 2026-01-01T08:08:08.000Z MX480_TOE date 88447 - - date set by root

<190>1 2026-01-01T08:08:08.000Z MX480_TOE mgd 87699 UI_CHILD_STATUS [junos@2636.1.1.1.2.25 command="/bin/date" pid="88447" status-code="0"] Cleanup child '/bin/date', PID 88447, status 0

Ability to configure NTP

<182>1 2025-07-24T10:41:28.618Z MX480_TOE mgd 21755 UI_CFG_AUDIT_OTHER [junos@2636.1.1.1.2.25 username="admin" action="set" pathname="[system ntp server 10.1.5.84\]" delimiter="" value=""] User 'admin' set: [system ntp server 10.1.5.84]

<182>1 2025-07-24T10:41:28.618Z MX480_TOE mgd 21755 UI_CFG_AUDIT_SET_SECRET [junos@2636.1.1.1.2.25 username="admin" action="set" pathname="[system ntp server 10.1.5.84 key\]"] User 'admin' set: [system ntp server 10.1.5.84 key]

<182>1 2025-07-24T10:41:28.618Z MX480_TOE mgd 21755 UI_CFG_AUDIT_SET [junos@2636.1.1.1.2.25 username="admin" action="set" pathname="[system ntp server 10.1.5.84 version\]" delimiter="" data="unconfigured" value="4"] User 'admin' set: [system ntp server 10.1.5.84 version] unconfigured -- "4"

<190>1 2025-07-24T10:41:28.618Z MX480_TOE mgd 21755 UI_CMDLINE_READ_LINE [junos@2636.1.1.1.2.25 username="admin" command="set system ntp server 10.1.5.84 key /* SECRET-DATA */ version 4 "] User 'admin', command 'set system ntp server 10.1.5.84 key /* SECRET-DATA */ version 4 '

Ability to administer the TOE locally<37>1 2025-08-04T10:45:23.451Z MX480_TOE login 86118 - - Login attempt for user acumensec from host [unknown]

<38>1 2025-08-04T10:45:27.602Z MX480_TOE login 86118 LOGIN_INFORMATION [junos@2636.1.1.1.2.25 username="acumensec" hostname="[unknown\]" tty-name="ttyu0"] User acumensec logged in from host [unknown] on device ttyu0

<190>1 2025-08-04T10:45:27.646Z MX480_TOE mgd 86163 UI_AUTH_EVENT [junos@2636.1.1.1.2.25 username="acumensec" authentication-level="j-security-admin"] Authenticated user 'acumensec' assigned to class 'j-security-admin'

<190>1 2025-08-04T10:45:27.646Z MX480_TOE mgd 86163 UI_LOGIN_EVENT [junos@2636.1.1.1.2.25 username="acumensec" class-name="j-security-admin" local-peer="" pid="86163" ssh-connection="" client-mode="cli"] User 'acumensec' login, class 'j-security-admin' [86163], ssh-connection '', client-mode 'cli'

Ability to manage the trusted public keys database

<182>1 2025-10-09T08:56:48.726Z MX480_TOE mgd 12101 UI_CFG_AUDIT_OTHER [junos@2636.1.1.1.2.25 username="admin" action="set" pathname="[system login user cctester authentication ssh-rsa /* SECRET-DATA */\]" delimiter="" value=""] User 'admin' set: [system login user cctester authentication ssh-rsa /* SECRET-DATA */]

<190>1 2025-10-09T08:56:48.726Z MX480_TOE mgd 12101 UI_CMDLINE_READ_LINE [junos@2636.1.1.1.2.25 username="admin" command="set system login user cctester authentication ssh-rsa /* SECRET-DATA */ "] User 'admin', command 'set system login user cctester authentication ssh-rsa /* SECRET-DATA */ '

FMT_SMR.2 None None
FPT_RPL.1 Detected replay attempt None <27>1 2025-10-17T12:24:14.040Z MX240 secure-dot1xd 24097 DOT1XD_MKA_DUPLICATE_OR_DELAYED_PDU_DETEC TED [junos@2636.1.1.1.2.29 cak-type="PRIMARY" mka-actor="0" interface-name="ge-0/0/0"] MKA PRIMARY actor #0 received duplicate or delayed PDU on interface: ge-0/0/0
FPT_SKP_EXT.1 None None
FPT_APW_EXT.1 None None
FPT_TST_EXT.1 None None
FPT_TUD_EXT.1 Initiation of update; result of the update attempt (success or failure) None

Initiation of update; result of the update attempt (success or failure)

<190>1 2025-08-11T05:41:24.812Z MX480_TOE mgd 49536 UI_CHILD_START [junos@2636.1.1.1.2.25 command="/usr/libexec/ui/package"] Starting child '/usr/libexec/ui/package'

<29>1 2025-08-11T05:41:24.814Z MX480_TOE mgd 49536 - - /usr/libexec/ui/package -X update /var/tmp/junos-vmhost-install-mx-x86-64-24.4R1.9.tgz

result of the update attempt (success or failure)

  • Success

** NOTE: status-code of “0”, states that the upgrade had been successful**

<190>1 2025-08-11T05:41:24.812Z MX480_TOE mgd 49536 UI_CHILD_START [junos@2636.1.1.1.2.25 command="/usr/libexec/ui/package"] Starting child '/usr/libexec/ui/package'

<29>1 2025-08-11T05:41:24.814Z MX480_TOE mgd 49536 - - /usr/libexec/ui/package -X update /var/tmp/junos-vmhost-install-mx-x86-64-24.4R1.9.tgz

<190>1 2025-08-11T05:48:16.808Z MX480_TOE mgd 49536 UI_CHILD_STATUS [junos@2636.1.1.1.2.25 command="/usr/libexec/ui/package" pid="71662" status-code="0"] Cleanup child '/usr/libexec/ui/package', PID 71662, status 0

  • failure

** NOTE: status-code other than “0”, states that the upgrade has failed**

<190>1 2025-08-20T05:55:26.865Z MX480_TOE mgd 81904 UI_CHILD_START [junos@2636.1.1.1.2.25 command="/opt/support/vmhost-pkg-support"] Starting child '/opt/support/vmhost-pkg-support'

<29>1 2025-08-20T05:55:26.867Z MX480_TOE mgd 81904 - - /opt/support/vmhost-pkg-support -c /var/tmp/junos-vmhost-install-mx-x86-64-24.4R1.9_modified.tgz

<190>1 2025-08-20T05:56:50.618Z MX480_TOE mgd 81904 UI_CHILD_STATUS [junos@2636.1.1.1.2.25 command="/opt/support/vmhost-pkg-support" pid="82345" status-code="256"] Cleanup child '/opt/support/vmhost-pkg-support', PID 82345, status 0x100

<29>1 2025-08-20T05:56:50.618Z MX480_TOE mgd 81904 UI_CHILD_EXITED [junos@2636.1.1.1.2.25 pid="82345" return-value="1" core-dump-status="" command="/opt/support/vmhost-pkg-support"] Child exited: PID 82345, status 1, command '/opt/support/vmhost-pkg-support'

FPT_STM_EXT.1 Discontinuous changes to time - either Administrator actuated or changed via an automated process For discontinuous changes to time: The old and new values for the time. Origin of the attempt to change time for success and failure (e.g., IP address).

Discontinuous changes to time - either Administrator actuated or changed via an automated process

Admin changed time:

<190>1 2025-08-06T06:59:31.596Z MX480_TOE mgd 87699 UI_CMDLINE_READ_LINE [junos@2636.1.1.1.2.25 username="admin" command="set date 202601010808.08 "] User 'admin', command 'set date 202601010808.08 '

<190>1 2025-08-06T06:59:31.598Z MX480_TOE mgd 87699 UI_CHILD_START [junos@2636.1.1.1.2.25 command="/bin/date"] Starting child '/bin/date'

<37>1 2026-01-01T08:08:08.000Z MX480_TOE date 88447 - - date set by root

<190>1 2026-01-01T08:08:08.000Z MX480_TOE mgd 87699 UI_CHILD_STATUS [junos@2636.1.1.1.2.25 command="/bin/date" pid="88447" status-code="0"] Cleanup child '/bin/date', PID 88447, status 0

Time change using NTP:

<102>1 2025-11-07T04:29:55.044Z MX480_TOE xntpd 67284 - - kernel reports TIME_ERROR: 0x41: Clock Unsynchronized

<102>1 2025-11-07T04:29:55.044Z MX480_TOE xntpd 67284 - - kernel reports TIME_ERROR: 0x41: Clock Unsynchronized

<103>1 2025-11-07T04:29:55.893Z MX480_TOE xntpd 67284 - - 1 7 0 32 32

<103>1 2025-11-07T04:29:57.895Z MX480_TOE xntpd 67284 - - 1 7 0 32 32

<103>1 2025-11-07T04:29:59.895Z MX480_TOE xntpd 67284 - - 1 7 0 32 32

<103>1 2025-11-07T04:30:01.898Z MX480_TOE xntpd 67284 - - 1 7 0 32 32

<14>1 2025-11-07T07:05:24.906Z MX480_TOE xntpd - NTPD_CHANGED_TIME [junos@2636.1.1.1.2.25 rate="9323.007043"] time reset +9323.007043 s

<101>1 2025-11-07T07:05:24.906Z MX480_TOE xntpd 67284 - - ntpd: time reset +9323.007043 s

admin@MX480_TOE:fips> show ntp associations

remote refid auth st t when poll reach delay offset jitter rootdelay rootdisp

=====================================================================================================================

*10.1.5.97 96.231.54.40 SKEY 2 u 22 64 3 0.451 -0.113 0.139 8.362 27.054

admin@MX480_TOE:fips>

FTA_SSL.3 The termination of a remote session by the session locking mechanism None

The termination of a remote session by the session locking mechanism

<14>1 2025-08-04T11:48:37.181Z MX480_TOE -cli - UI_CLI_IDLE_TIMEOUT [junos@2636.1.1.1.2.25 username="acumensec"] Idle timeout for user 'acumensec' exceeded and session terminated

<190>1 2025-08-04T11:48:37.181Z MX480_TOE mgd 89124 UI_LOGOUT_EVENT [junos@2636.1.1.1.2.25 username="acumensec"] User 'acumensec' logout

<38>1 2025-08-04T11:48:37.183Z MX480_TOE sshd 89122 - - Received disconnect from 10.1.5.84 port 50294:11: disconnected by user

<38>1 2025-08-04T11:48:37.183Z MX480_TOE sshd 89122 - - Disconnected from user acumensec 10.1.5.84 port 50294

FTA_SSL.4 The termination of an interactive session None

The termination of an interactive session

<190>1 2025-08-04T09:45:46.370Z MX480_TOE mgd 83269 UI_CMDLINE_READ_LINE [junos@2636.1.1.1.2.25 username="acumensec" command="exit "] User 'acumensec', command 'exit '

<190>1 2025-08-04T09:45:46.370Z MX480_TOE mgd 83269 UI_LOGOUT_EVENT [junos@2636.1.1.1.2.25 username="acumensec"] User 'acumensec' logout

FTA_SSL_EXT.1 (if “terminate the session” is selected) The termination of a local session by the session locking mechanism None

The termination of a local session by the session locking mechanism

<14>1 2025-08-04T10:46:32.246Z MX480_TOE -cli - UI_CLI_IDLE_TIMEOUT [junos@2636.1.1.1.2.25 username="acumensec"] Idle timeout for user 'acumensec' exceeded and session terminated

<190>1 2025-08-04T10:46:32.247Z MX480_TOE mgd 86163 UI_LOGOUT_EVENT [junos@2636.1.1.1.2.25 username="acumensec"] User 'acumensec' logout

FTA_TAB.1 None None
FTP_ITC.1
  • Initiation of the trusted channel.
  • Termination of the trusted channel.
  • Failure of the trusted channel functions.
  • None
  • None
  • Reason for failure
  • Initiation of the trusted channel.

<38>1 2025-10-09T08:21:56.548Z MX480_TOE sshd 11107 - - Accepted publickey for syslog-mon from 10.1.5.84 port 49514 ssh2: ECDSA SHA256:nh0jpMNtA7wsC1Cti+f/VEFD8CjkZvsn+Qi1UDwt7LM

<190>1 2025-10-09T08:21:56.640Z MX480_TOE mgd 11111 UI_AUTH_EVENT [junos@2636.1.1.1.2.25 username="syslog-mon" authentication-level="j-monitor"] Authenticated user 'syslog-mon' assigned to class 'j-monitor'

<190>1 2025-10-09T08:21:56.641Z MX480_TOE mgd 11111 UI_LOGIN_EVENT [junos@2636.1.1.1.2.25 username="syslog-mon" class-name="j-monitor" local-peer="" pid="11111" ssh-connection="10.1.5.84 49514 10.1.2.158 22" client-mode="cli"] User 'syslog-mon' login, class 'j-monitor' [11111], ssh-connection '10.1.5.84 49514 10.1.2.158 22', client-mode 'cli'

  • Termination of the trusted channel.

<30>1 2025-10-09T08:27:14.238Z MX480_TOE mgd 11110 UI_NETCONF_MONITORING_DELETE [junos@2636.1.1.1.2.25 message="11110"] Netconf session with pid '11110' is being deleted

<190>1 2025-10-09T08:27:14.247Z MX480_TOE mgd 11110 UI_LOGOUT_EVENT [junos@2636.1.1.1.2.25 username="syslog-mon"] User 'syslog-mon' logout

  • Failure of the trusted channel functions.

<38>1 2025-10-09T08:36:32.385Z MX480_TOE sshd 11646 - - Unable to negotiate with 10.1.5.84 port 47950: no matching MAC found. Their offer: hmac-md5 [preauth]

FTP_TRP.1/Admin
  • Initiation of the trusted path.
  • Termination of the trusted path.
  • Failure of the trusted path functions.
  • None
  • None
  • Reason for failure
  • Initiation of the trusted path.

<38>1 2025-07-09T12:06:43.690Z MX480_TOE sshd 23064 - - Accepted keyboard-interactive/pam for acumensec from 10.1.5.84 port 35624 ssh2

<190>1 2025-07-09T12:06:43.780Z MX480_TOE mgd 23070 UI_AUTH_EVENT [junos@2636.1.1.1.2.25 username="acumensec" authentication-level="j-security-admin"] Authenticated user 'acumensec' assigned to class 'j-security-admin'

<190>1 2025-07-09T12:06:43.780Z MX480_TOE mgd 23070 UI_LOGIN_EVENT [junos@2636.1.1.1.2.25 username="acumensec" class-name="j-security-admin" local-peer="" pid="23070" ssh-connection="10.1.5.84 35624 10.1.2.158 22" client-mode="cli"] User 'acumensec' login, class 'j-security-admin' [23070], ssh-connection '10.1.5.84 35624 10.1.2.158 22', client-mode 'cli'

  • Termination of the trusted path.

<38>1 2025-07-09T12:08:55.986Z MX480_TOE sshd 23068 - - Received disconnect from 10.1.5.84 port 35624:11: disconnected by user

<38>1 2025-07-09T12:08:55.986Z MX480_TOE sshd 23068 - - Disconnected from user acumensec 10.1.5.84 port 35624

  • Failure of the trusted path functions.

<38>1 2025-08-12T11:53:11.090Z MX480_TOE sshd 30530 - - Unable to negotiate with 10.1.2.65 port 49874: no matching cipher found. Their offer: aes192-ctr [preauth]

In addition, Juniper Networks recommends:

  • To capture all changes to the configuration.

  • To store logging information remotely.

For more information on log details, see Specifying Log File Size, Number, and Archiving Properties