Event Logging Overview
The evaluated configuration requires the auditing of configuration changes through the system log.
In addition, Junos OS can:
-
Send automated responses to audit events (syslog entry creation).
-
Allow authorized managers to examine audit logs.
-
Send audit files to external servers.
-
Allow authorized managers to return the system to a known state.
The logging for the evaluated configuration must capture the events. The logging events are listed below:
Table 1 shows sample for syslog auditing for NDcPPv3.0e:
| Requirement | Auditable Events | Additional Audit Record Contents | Audit Records |
|---|---|---|---|
| FAU_GEN.1 | None | None |
Note: There is no manual startup/shutdown of the local audit function, which is tied to startup/shutdown of the TOE itself, logs for which implicitly indicate the audit function stopping and starting as well. TOE Shutdown: <45>1 2025-07-04T23:12:32.753Z MX480_TOE eventd 20463 SYSTEM_SHUTDOWN [junos@2636.1.1.1.2.25 type="shutdown" username="admin" time="Fri Jul 4 23:08:54 2025" message="no message"] System shutdown by admin at Fri Jul 4 23:08:54 2025: no message TOE Startup: <45>1 2025-07-04T23:12:32.754Z MX480_TOE eventd 20463 SYSTEM_OPERATIONAL - System is operational
Login: <38>1 2025-07-09T12:06:43.690Z MX480_TOE sshd 23064 - - Accepted keyboard-interactive/pam for acumensec from 10.1.5.84 port 35624 ssh2 <190>1 2025-07-09T12:06:43.780Z MX480_TOE mgd 23070 UI_AUTH_EVENT [junos@2636.1.1.1.2.25 username="acumensec" authentication-level="j-security-admin"] Authenticated user 'acumensec' assigned to class 'j-security-admin' <190>1 2025-07-09T12:06:43.780Z MX480_TOE mgd 23070 UI_LOGIN_EVENT [junos@2636.1.1.1.2.25 username="acumensec" class-name="j-security-admin" local-peer="" pid="23070" ssh-connection="10.1.5.84 35624 10.1.2.158 22" client-mode="cli"] User 'acumensec' login, class 'j-security-admin' [23070], ssh-connection '10.1.5.84 35624 10.1.2.158 22', client-mode 'cli' Logout <38>1 2025-07-09T12:08:55.986Z MX480_TOE sshd 23068 - - Received disconnect from 10.1.5.84 port 35624:11: disconnected by user <38>1 2025-07-09T12:08:55.986Z MX480_TOE sshd 23068 - - Disconnected from user acumensec 10.1.5.84 port 35624
<182>1 2025-07-09T11:11:54.326Z MX480_TOE mgd 22519 UI_CFG_AUDIT_SET [junos@2636.1.1.1.2.25 username="admin" action="set" pathname="[system syslog file audit_file any\]" delimiter="" data="unconfigured" value="any"] User 'admin' set: [system syslog file audit_file any] unconfigured -- "any" <190>1 2025-07-09T11:11:54.326Z MX480_TOE mgd 22519 UI_CMDLINE_READ_LINE [junos@2636.1.1.1.2.25 username="admin" command="set system syslog file audit_file any any "] User 'admin', command 'set system syslog file audit_file any any '
Import of cryptographic keys (SSH): <182>1 2025-08-12T10:54:36.309Z MX480_TOE mgd 21496 UI_CFG_AUDIT_OTHER [junos@2636.1.1.1.2.25 username="admin" action="set" pathname="[system login user cctester authentication ssh-rsa /* SECRET-DATA */\]" delimiter="" value=""] User 'admin' set: [system login user cctester authentication ssh-rsa /* SECRET-DATA */] <190>1 2025-08-12T10:54:36.309Z MX480_TOE mgd 21496 UI_CMDLINE_READ_LINE [junos@2636.1.1.1.2.25 username="admin" command="set system login user cctester authentication ssh-rsa /* SECRET-DATA */ "] User 'admin', command 'set system login user cctester authentication ssh-rsa /* SECRET-DATA */ ' Deletion of cryptographic keys (SSH): <190>1 2025-08-12T10:57:13.866Z MX480_TOE mgd 21496 UI_CMDLINE_READ_LINE [junos@2636.1.1.1.2.25 username="admin" command="delete system login user cctester authentication ssh-rsa /* SECRET-DATA */ "] User 'admin', command 'delete system login user cctester authentication ssh-rsa /* SECRET-DATA */ ' <182>1 2025-08-12T10:57:13.866Z MX480_TOE mgd 21496 UI_CFG_AUDIT_OTHER [junos@2636.1.1.1.2.25 username="admin" action="delete" pathname="[system login user cctester authentication ssh-rsa /* SECRET-DATA */\]" delimiter="" value=""] User 'admin' delete: [system login user cctester authentication ssh-rsa /* SECRET-DATA */]
**NOTE: The logs mention data=”unconfigured” as the old value even when resetting an existing password to mask the sensitive information. <182>1 2025-07-09T12:39:20.230Z MX480_TOE mgd 22148 UI_CFG_AUDIT_SET [junos@2636.1.1.1.2.25 username="admin" action="set" pathname="[system login user cctester authentication\]" delimiter="" data="unconfigured" value="plain-text-password"] User 'admin' set: [system login user cctester authentication] unconfigured -- "plain-text-password" <190>1 2025-07-09T12:39:32.340Z MX480_TOE mgd 22148 UI_CMDLINE_READ_LINE [junos@2636.1.1.1.2.25 username="admin" command="set system login user cctester authentication plain-text-password "] User 'admin', command 'set system login user cctester authentication plain-text-password ' |
| FAU_GEN.2 | None | None | |
| FAU_STG_EXT.1 | Configuration of local audit settings. | Identity of account making changes to the audit configuration. |
Configuration of local audit settings. <182>1 2025-07-09T11:11:54.326Z MX480_TOE mgd 22519 UI_CFG_AUDIT_SET [junos@2636.1.1.1.2.25 username="admin" action="set" pathname="[system syslog file audit_file any\]" delimiter="" data="unconfigured" value="any"] User 'admin' set: [system syslog file audit_file any] unconfigured -- "any" <190>1 2025-07-09T11:11:54.326Z MX480_TOE mgd 22519 UI_CMDLINE_READ_LINE [junos@2636.1.1.1.2.25 username="admin" command="set system syslog file audit_file any any "] User 'admin', command 'set system syslog file audit_file any any ' |
| FCS_CKM.1 | None | None | |
| FCS_CKM.2 | None | None | |
| FCS_CKM.4 | None | None | |
| FCS_COP.1/DataEncryption | None | None | |
| FCS_COP.1/SigGen | None | None | |
| FCS_COP.1/Hash | None | None | |
| FCS_COP.1/KeyedHash | None | None | |
| FCS_MACSEC_EXT.1 | Session establishment | Secure Channel Identifier (SCI) |
<30>1 2025-09-17T14:19:21.580Z MX240 secure-dot1xd 23083 DOT1XD_MKA_SECURE_CHANNEL_CREATED [junos@2636.1.1.1.2.29 mac-address="7c:25:86:ab:28:40" interface-name="ge-0/0/0"] Macsec receive secure channel created for 7c:25:86:ab:28:40 on interface ge-0/0/0 <28>1 2025-09-17T14:19:31.043Z MX240 secure-dot1xd 23083 DOT1XD_MACSEC_SC_CAK_ACTIVATED [junos@2636.1.1.1.2.29 interface-name="ge-0/0/0" sc-id0="5800BB0A680C0001" sc-id1="7C2586AB28400001" pre-shared-key="1234567890"] ifd: ge-0/0/0 sci-out:5800BB0A680C0001 sci-in:7C2586AB28400001 ckn: 1234567890 |
| FCS_MACSEC_EXT.3 | Creation and update of SAK | Creation and update times |
Creation of SAK: <30>1 2025-10-14T11:24:42.053Z MX240 secure-dot1xd 21596 DOT1XD_MKA_SECURE_CHANNEL_CREATED [junos@2636.1.1.1.2.29 mac-address="7c:25:86:ab:28:40" interface-name="ge-0/0/0"] Macsec receive secure channel created for 7c:25:86:ab:28:40 on interface ge-0/0/0 Update of SAK: <30>1 2025-09-29T13:26:29.994Z MX240 secure-dot1xd 23083 DOT1XD_MKA_SAK_REKEY_EVENT [junos@2636.1.1.1.2.29 interface-name="ge-0/0/0"] MKA sak-rekey event started for the interface: ge-0/0/0 <30>1 2025-09-29T13:26:29.994Z MX240 secure-dot1xd 23083 DOT1XD_MKA_SA_KEY_ROLLOVER [junos@2636.1.1.1.2.29 interface-name="ge-0/0/0"] Macsec secure association key rolled over on interface ge-0/0/0 |
| FCS_MACSEC_EXT.4 | Creation of CA | Connectivity Association Key Names (CKNs) |
<30>1 2025-10-14T11:24:42.053Z MX240 secure-dot1xd 21596 DOT1XD_MKA_SECURE_CHANNEL_CREATED [junos@2636.1.1.1.2.29 mac-address="7c:25:86:ab:28:40" interface-name="ge-0/0/0"] Macsec receive secure channel created for 7c:25:86:ab:28:40 on interface ge-0/0/0 <30>1 2025-10-14T11:24:42.601Z MX240 secure-dot1xd 21596 DOT1XD_MKA_SECURE_ASSOCIATION_ESTABLISHED [junos@2636.1.1.1.2.29 sequence-number="0" interface-name="ge-0/0/0"] Macsec secure association established with an:0 on interface ge-0/0/0 <28>1 2025-10-14T11:24:42.601Z MX240 secure-dot1xd 21596 DOT1XD_MACSEC_SC_PRIMARY_CAK_IN_USE [junos@2636.1.1.1.2.29 interface-name="ge-0/0/0" pre-shared-key="ABCDEF0123456789ABCDEF0123456789"] ifd: ge-0/0/0 primary ckn: ABCDEF0123456789ABCDEF0123456789 is in-use <28>1 2025-10-14T11:24:48.281Z MX240 secure-dot1xd 21596 DOT1XD_MACSEC_SC_CAK_ACTIVATED [junos@2636.1.1.1.2.29 interface-name="ge-0/0/0" sc-id0="5800BB0A680C0001" sc-id1="7C2586AB28400001" pre-shared-key="ABCDEF0123456789ABCDEF0123456789"] ifd: ge-0/0/0 sci-out:5800BB0A680C0001 sci-in:7C2586AB28400001 ckn: ABCDEF0123456789ABCDEF0123456789 |
| FCS_RBG_EXT.1 | None | None | |
| FCS_SSH_EXT.1 | Failure to establish SSH connection | Reason for failure and [Non-TOE endpoint of attempted connection (IP Address)] |
Failure to establish SSH connection Unsupported cipher <38>1 2025-08-12T11:53:11.090Z MX480_TOE sshd 30530 - - Unable to negotiate with 10.1.2.65 port 49874: no matching cipher found. Their offer: aes192-ctr [preauth] Unsupported hashing algorithm <38>1 2025-08-12T12:03:26.860Z MX480_TOE sshd 24607 - - Unable to negotiate with 10.1.2.65 port 55976: no matching MAC found. Their offer: hmac-md5 [preauth] Unsupported key exchange method <38>1 2025-08-12T12:05:48.942Z MX480_TOE sshd 24672 - - Unable to negotiate with 10.1.2.65 port 59712: no matching key exchange method found. Their offer: diffie-hellman-group14-sha1,ext-info-c,kex-strict-c-v00@openssh.com [preauth] |
| Establishment of SSH connection | [Non-TOE endpoint of attempted connection (IP Address)] |
Establishment of SSH connection <38>1 2025-07-09T12:06:43.690Z MX480_TOE sshd 23064 - - Accepted keyboard-interactive/pam for acumensec from 10.1.5.84 port 35624 ssh2 <190>1 2025-07-09T12:06:43.780Z MX480_TOE mgd 23070 UI_AUTH_EVENT [junos@2636.1.1.1.2.25 username="acumensec" authentication-level="j-security-admin"] Authenticated user 'acumensec' assigned to class 'j-security-admin' <190>1 2025-07-09T12:06:43.780Z MX480_TOE mgd 23070 UI_LOGIN_EVENT [junos@2636.1.1.1.2.25 username="acumensec" class-name="j-security-admin" local-peer="" pid="23070" ssh-connection="10.1.5.84 35624 10.1.2.158 22" client-mode="cli"] User 'acumensec' login, class 'j-security-admin' [23070], ssh-connection '10.1.5.84 35624 10.1.2.158 22', client-mode 'cli' |
|
| Termination of SSH connection session | [Non-TOE endpoint of attempted connection (IP Address)] |
Termination of SSH connection session <38>1 2025-07-09T12:08:55.986Z MX480_TOE sshd 23068 - - Received disconnect from 10.1.5.84 port 35624:11: disconnected by user <38>1 2025-07-09T12:08:55.986Z MX480_TOE sshd 23068 - - Disconnected from user acumensec 10.1.5.84 port 35624 |
|
| Dropping of packet(s) outside defined size limits | [Packet Size] |
<38>1 2025-09-30T11:01:46.335Z MX480_TOE sshd 65440 - - Accepted password for admin from 10.1.5.84 port 44272 ssh2 <38>1 2025-09-30T11:01:46.339Z MX480_TOE sshd 65442 - - Potential replay attack detected on SSH connection initiated from 10.1.5.84:44272 <37>1 2025-09-30T11:01:46.339Z MX480_TOE sshd - SSH_MSG_REPLAY_DETECT [junos@2636.1.1.1.2.25 source-address="10.1.5.84" source-port="44272"] Potential replay attack detected on SSH connection initiated from 10.1.5.84:44272 <38>1 2025-09-30T11:01:46.340Z MX480_TOE sshd 65442 - - Bad packet length 262145. <28>1 2025-09-30T11:01:46.341Z MX480_TOE inetd 21046 - - /usr/sbin/sshd[65440]: exited, status 255 |
|
| FCS_SSHS_EXT.1 | No events specified | None | None |
| FCS_NTP_EXT.1 |
|
Identity of new/removed time server |
<182>1 2025-07-24T10:41:28.618Z MX480_TOE mgd 21755 UI_CFG_AUDIT_OTHER [junos@2636.1.1.1.2.25 username="admin" action="set" pathname="[system ntp server 10.1.5.84\]" delimiter="" value=""] User 'admin' set: [system ntp server 10.1.5.84] <182>1 2025-07-24T10:41:28.618Z MX480_TOE mgd 21755 UI_CFG_AUDIT_SET_SECRET [junos@2636.1.1.1.2.25 username="admin" action="set" pathname="[system ntp server 10.1.5.84 key\]"] User 'admin' set: [system ntp server 10.1.5.84 key] <182>1 2025-07-24T10:41:28.618Z MX480_TOE mgd 21755 UI_CFG_AUDIT_SET [junos@2636.1.1.1.2.25 username="admin" action="set" pathname="[system ntp server 10.1.5.84 version\]" delimiter="" data="unconfigured" value="4"] User 'admin' set: [system ntp server 10.1.5.84 version] unconfigured -- "4" <190>1 2025-07-24T10:41:28.618Z MX480_TOE mgd 21755 UI_CMDLINE_READ_LINE [junos@2636.1.1.1.2.25 username="admin" command="set system ntp server 10.1.5.84 key /* SECRET-DATA */ version 4 "] User 'admin', command 'set system ntp server 10.1.5.84 key /* SECRET-DATA */ version 4 '
<190>1 2025-07-24T10:43:05.455Z MX480_TOE mgd 21755 UI_CMDLINE_READ_LINE [junos@2636.1.1.1.2.25 username="admin" command="delete system ntp server 10.1.5.84 "] User 'admin', command 'delete system ntp server 10.1.5.84 ' <182>1 2025-07-24T10:43:05.455Z MX480_TOE mgd 21755 UI_CFG_AUDIT_OTHER [junos@2636.1.1.1.2.25 username="admin" action="delete" pathname="[system ntp server 10.1.5.84\]" delimiter="" value=""] User 'admin' delete: [system ntp server 10.1.5.84] |
| FIA_UIA_EXT.1 | All use of identification and authentication mechanism | Origin of the attempt (e.g., IP address) |
All use of identification and authentication mechanism Local Successful Login <37>1 2025-07-11T16:17:50.080Z MX480_TOE login 76412 - - Login attempt for user acumensec from host [unknown] <38>1 2025-07-11T16:17:53.680Z MX480_TOE login 76412 LOGIN_INFORMATION [junos@2636.1.1.1.2.25 username="acumensec" hostname="[unknown\]" tty-name="ttyu0"] User acumensec logged in from host [unknown] on device ttyu0 <190>1 2025-07-11T16:17:53.726Z MX480_TOE mgd 76415 UI_AUTH_EVENT [junos@2636.1.1.1.2.25 username="acumensec" authentication-level="j-security-admin"] Authenticated user 'acumensec' assigned to class 'j-security-admin' <190>1 2025-07-11T16:17:53.726Z MX480_TOE mgd 76415 UI_LOGIN_EVENT [junos@2636.1.1.1.2.25 username="acumensec" class-name="j-security-admin" local-peer="" pid="76415" ssh-connection="" client-mode="cli"] User 'acumensec' login, class 'j-security-admin' [76415], ssh-connection '', client-mode 'cli' Local Unsuccessful Login <37>1 2025-07-11T16:05:45.358Z MX480_TOE login 75983 - - Login attempt for user acumensec from host [unknown] <35>1 2025-07-11T16:05:46.548Z MX480_TOE login 75983 PAM_UNIX_LOC_PASSWD_AUTH [junos@2636.1.1.1.2.25 username="acumensec" result="failed"] local password authentication of user 'acumensec' failed <35>1 2025-07-11T16:05:46.549Z MX480_TOE login 75983 LOGIN_PAM_AUTHENTICATION_ERROR [junos@2636.1.1.1.2.25 username="acumensec"] Failed password for user acumensec <37>1 2025-07-11T16:05:46.549Z MX480_TOE login 75983 LOGIN_FAILED [junos@2636.1.1.1.2.25 username="acumensec" source-address="ttyu0"] Login failed for user acumensec from host ttyu0 Remote Successful Password-Based Login <38>1 2025-08-04T11:00:37.144Z MX480_TOE sshd 86747 - - Accepted password for acumensec from 10.1.5.84 port 36318 ssh2 <190>1 2025-08-04T11:00:37.235Z MX480_TOE mgd 86751 UI_AUTH_EVENT [junos@2636.1.1.1.2.25 username="acumensec" authentication-level="j-security-admin"] Authenticated user 'acumensec' assigned to class 'j-security-admin' <190>1 2025-08-04T11:00:37.235Z MX480_TOE mgd 86751 UI_LOGIN_EVENT [junos@2636.1.1.1.2.25 username="acumensec" class-name="j-security-admin" local-peer="" pid="86751" ssh-connection="10.1.5.84 36318 10.1.2.158 22" client-mode="cli"] User 'acumensec' login, class 'j-security-admin' [86751], ssh-connection '10.1.5.84 36318 10.1.2.158 22', client-mode 'cli' Remote Unsuccessful Password-Based Login <35>1 2025-07-11T16:39:14.888Z MX480_TOE sshd - PAM_UNIX_LOC_PASSWD_AUTH [junos@2636.1.1.1.2.25 username="acumensec" result="failed"] local password authentication of user 'acumensec' failed <15>1 2025-07-11T16:39:14.888Z MX480_TOE sshd - PAM_USER_LOCK_USER [junos@2636.1.1.1.2.25 event-function-name="pam_sm_authenticate" username="acumensec"] (pam_sm_authenticate): DEBUG: PAM_USER: acumensec <15>1 2025-07-11T16:39:14.889Z MX480_TOE sshd - PAM_USER_LOCK_UPD_LOCK_ATTEMPTS [junos@2636.1.1.1.2.25 event-function-name="pam_sm_authenticate" username="acumensec" num-msgs-forward="1"] (pam_sm_authenticate): DEBUG: Updating lock-attempts of user: acumensec attempts: 1 <35>1 2025-07-11T16:39:14.889Z MX480_TOE sshd 77211 - - error: PAM: Authentication error for acumensec from 10.1.5.84 <37>1 2025-07-11T16:39:14.890Z MX480_TOE sshd - SSHD_LOGIN_FAILED [junos@2636.1.1.1.2.25 username="acumensec" source-address="10.1.5.84"] Login failed for user 'acumensec' from host '10.1.5.84' Remote Successful Public Key-Based Login <38>1 2025-07-14T20:06:49.571Z MX480_TOE sshd 40869 - - Accepted publickey for admin from 10.1.5.84 port 39202 ssh2: RSA SHA256:z1HjGXyPNrVziK39ieCsdzP99cDVXpZIMvPtuAiTrps <190>1 2025-07-14T20:06:49.680Z MX480_TOE mgd 40873 UI_AUTH_EVENT [junos@2636.1.1.1.2.25 username="admin" authentication-level="j-security-admin"] Authenticated user 'admin' assigned to class 'j-security-admin' <190>1 2025-07-14T20:06:49.680Z MX480_TOE mgd 40873 UI_LOGIN_EVENT [junos@2636.1.1.1.2.25 username="admin" class-name="j-security-admin" local-peer="" pid="40873" ssh-connection="10.1.5.84 39202 10.1.2.158 22" client-mode="cli"] User 'admin' login, class 'j-security-admin' [40873], ssh-connection '10.1.5.84 39202 10.1.2.158 22', client-mode 'cli' Remote Unsuccessful Public Key-Based Login <38>1 2025-09-04T09:44:20.435Z MX480_TOE sshd 93275 - - Connection closed by authenticating user tester 10.1.5.84 port 55022 [preauth] <28>1 2025-09-04T09:44:20.436Z MX480_TOE inetd 20984 - - /usr/sbin/sshd[93275]: exited, status 255 |
| FIA_AFL.1 | Unsuccessful login attempts limit is met or exceeded | Origin of the attempt (e.g., IP address) |
Unsuccessful login attempts limit is met or exceeded Aug 15 18:05:17 2025 MX480_TOE sshd[94713]: error: PAM: Authentication error for tester from 10.1.5.84 Aug 15 18:05:17 2025 MX480_TOE sshd: SSHD_LOGIN_FAILED: Login failed for user 'tester' from host '10.1.5.84' Aug 15 18:05:18 2025 MX480_TOE sshd[94713]: error: PAM: Authentication error for tester from 10.1.5.84 Aug 15 18:05:18 2025 MX480_TOE sshd: SSHD_LOGIN_FAILED: Login failed for user 'tester' from host '10.1.5.84' Aug 15 18:05:25 2025 MX480_TOE sshd: LIBJNX_LOGIN_ACCOUNT_LOCKED: Account for user 'tester' has been locked out from logins Aug 15 18:05:25 2025 MX480_TOE sshd: PAM_USER_LOCK_LOGIN_REQUESTS_DENIED: Login requests from host '10.1.5.84' are denied Aug 15 18:05:25 2025 MX480_TOE sshd[94713]: error: PAM: Authentication error for tester from 10.1.5.84 Aug 15 18:05:25 2025 MX480_TOE sshd: SSHD_LOGIN_FAILED: Login failed for user 'tester' from host '10.1.5.84' Aug 15 18:05:40 2025 MX480_TOE sshd: SSHD_LOGIN_ATTEMPTS_THRESHOLD: Threshold for unsuccessful authentication attempts (3) reached by user 'tester' Aug 15 18:05:40 2025 MX480_TOE sshd[94713]: Disconnecting authenticating user tester 10.1.5.84 port 48596: Too many password failures for tester [preauth] Aug 15 18:05:40 2025 MX480_TOE sshd[94714]: Disconnecting authenticating user tester 10.1.5.84 port 48596: Too many password failures for tester Aug 15 18:05:40 2025 MX480_TOE inetd[23345]: /usr/sbin/sshd[94713]: exited, status 255 |
| FIA_PMG_EXT.1 | None | None | |
| FIA_UAU.7 | None | None | |
| FMT_MOF.1/ManualUpdate | Any attempt to initiate a manual update | None |
Any attempt to initiate a manual update <190>1 2025-08-11T05:41:24.812Z MX480_TOE mgd 49536 UI_CHILD_START [junos@2636.1.1.1.2.25 command="/usr/libexec/ui/package"] Starting child '/usr/libexec/ui/package' <29>1 2025-08-11T05:41:24.814Z MX480_TOE mgd 49536 - - /usr/libexec/ui/package -X update /var/tmp/junos-vmhost-install-mx-x86-64-24.4R1.9.tgz |
| FMT_MOF.1/Functions | None | None | |
| FMT_MOF.1/Services | None | None | |
| FMT_MTD.1/CoreData | None | None | |
| FMT_MTD.1/CryptoKeys | None | None | |
| FMT_SMF.1 | All management activities of TSF data. | None |
Ability to administer the TOE remotely <38>1 2025-07-09T12:06:43.690Z MX480_TOE sshd 23064 - - Accepted keyboard-interactive/pam for acumensec from 10.1.5.84 port 35624 ssh2 <190>1 2025-07-09T12:06:43.780Z MX480_TOE mgd 23070 UI_AUTH_EVENT [junos@2636.1.1.1.2.25 username="acumensec" authentication-level="j-security-admin"] Authenticated user 'acumensec' assigned to class 'j-security-admin' <190>1 2025-07-09T12:06:43.780Z MX480_TOE mgd 23070 UI_LOGIN_EVENT [junos@2636.1.1.1.2.25 username="acumensec" class-name="j-security-admin" local-peer="" pid="23070" ssh-connection="10.1.5.84 35624 10.1.2.158 22" client-mode="cli"] User 'acumensec' login, class 'j-security-admin' [23070], ssh-connection '10.1.5.84 35624 10.1.2.158 22', client-mode 'cli' Ability to configure the access banner <182>1 2025-08-04T05:48:50.806Z MX480_TOE mgd 69167 UI_CFG_AUDIT_SET [junos@2636.1.1.1.2.25 username="admin" action="set" pathname="[system login message\]" delimiter="" data="unconfigured" value="This is a LOGIN message for MX 480.\\nAuthorized users only !!!"] User 'admin' set: [system login message] unconfigured -- "This is a LOGIN message for MX 480.\nAuthorized users only !!!" <190>1 2025-08-04T05:48:50.806Z MX480_TOE mgd 69167 UI_CMDLINE_READ_LINE [junos@2636.1.1.1.2.25 username="admin" command="set system login message \"This is a LOGIN messagefor MX 480.\\nAuthorized users only !!!\" "] User 'admin', command 'set system login message "This is a LOGIN message for MX 480.\nAuthorized users only !!!" ' Ability to configure the remote session inactivity time before session termination <182>1 2025-08-04T10:35:29.803Z MX480_TOE mgd 71233 UI_CFG_AUDIT_SET [junos@2636.1.1.1.2.25 username="admin" action="set" pathname="[system login class security-admin idle-timeout\]" delimiter="" data="unconfigured" value="1"] User 'admin' set: [system login class security-admin idle-timeout] unconfigured -- "1" <190>1 2025-08-04T10:35:29.804Z MX480_TOE mgd 71233 UI_CMDLINE_READ_LINE [junos@2636.1.1.1.2.25 username="admin" command="set system login class security-admin idle-timeout 1 "] User 'admin', command 'set system login class security-admin idle-timeout 1 ' Ability to update the TOE, and to verify the updates using digital signature capability prior to installing those updates <190>1 2025-08-11T05:41:24.812Z MX480_TOE mgd 49536 UI_CHILD_START [junos@2636.1.1.1.2.25 command="/usr/libexec/ui/package"] Starting child '/usr/libexec/ui/package' <29>1 2025-08-11T05:41:24.814Z MX480_TOE mgd 49536 - - /usr/libexec/ui/package -X update /var/tmp/junos-vmhost-install-mx-x86-64-24.4R1.9.tgz <190>1 2025-08-11T05:48:16.808Z MX480_TOE mgd 49536 UI_CHILD_STATUS [junos@2636.1.1.1.2.25 command="/usr/libexec/ui/package" pid="71662" status-code="0"] Cleanup child '/usr/libexec/ui/package', PID 71662, status 0 <118>1 2025-08-11T05:57:17.200Z MX480_TOE kernel - - - Verified os-kernel-prd-x86-64-20241104 signed by PackageProductionECP256_2024 method ECDSA256+SHA256 <118>1 2025-08-11T05:57:17.200Z MX480_TOE kernel - - - Verified os-libs-15-x86-64-20241104 signed by PackageProductionECP256_2024 method ECDSA256+SHA256 <118>1 2025-08-11T05:57:17.200Z MX480_TOE kernel - - - Verified os-runtime-x86-64-20241104 signed by PackageProductionECP256_2024 method ECDSA256+SHA256 <118>1 2025-08-11T05:57:17.200Z MX480_TOE kernel - - - Verified os-package-20241014 signed by Package ProductionECP256_2024 method ECDSA256+SHA256 Ability to start and stop services Starting services <182>1 2025-10-09T09:32:27.377Z MX480_TOE mgd 12714 UI_CFG_AUDIT_OTHER [junos@2636.1.1.1.2.25 username="admin" action="set" pathname="[system services netconf ssh\]" delimiter="" value=""] User 'admin' set: [system services netconf ssh] <190>1 2025-10-09T09:32:27.377Z MX480_TOE mgd 12714 UI_CMDLINE_READ_LINE [junos@2636.1.1.1.2.25 username="admin" command="set system services netconf ssh "] User 'admin', command 'set system services netconf ssh ' Stopping services <190>1 2025-10-09T09:34:59.262Z MX480_TOE mgd 12714 UI_CMDLINE_READ_LINE [junos@2636.1.1.1.2.25 username="admin" command="delete system services netconf ssh "] User 'admin', command 'delete system services netconf ssh ' <182>1 2025-10-09T09:34:59.262Z MX480_TOE mgd 12714 UI_CFG_AUDIT_OTHER [junos@2636.1.1.1.2.25 username="admin" action="delete" pathname="[system services netconf ssh\]" delimiter="" value=""] User 'admin' delete: [system services netconf ssh] Ability to configure local audit behaviour (e.g. changes to storage locations for audit; changes to behaviour when local audit storage space is full, changes to local audit storage size) <182>1 2025-07-14T09:48:54.261Z MX480_TOE mgd 57387 UI_CFG_AUDIT_SET [junos@263 6.1.1.1.2.25 username="admin" action="set" pathname="[system syslog file syslog archive size\]" delimiter="\"" data="10m" value="11m"] User 'admin' set: [system syslog file syslog archive size] "10m -- "11m" <190>1 2025-07-14T09:48:54.261Z MX480_TOE mgd 57387 UI_CMDLINE_READ_LINE [junos @2636.1.1.1.2.25 username="admin" command="set system syslog file syslog archiv e size 11m "] User 'admin', command 'set system syslog file syslog archive size 11m ' Ability to modify the behaviour of the transmission of audit data to an external IT entity <182>1 2025-10-09T09:32:27.377Z MX480_TOE mgd 12714 UI_CFG_AUDIT_OTHER [junos@2636.1.1.1.2.25 username="admin" action="set" pathname="[system services netconf ssh\]" delimiter="" value=""] User 'admin' set: [system services netconf ssh] <190>1 2025-10-09T09:32:27.377Z MX480_TOE mgd 12714 UI_CMDLINE_READ_LINE [junos@2636.1.1.1.2.25 username="admin" command="set system services netconf ssh "] User 'admin', command 'set system services netconf ssh ' Ability to manage the cryptographic keys <182>1 2025-08-12T10:54:36.309Z MX480_TOE mgd 21496 UI_CFG_AUDIT_OTHER [junos@2636.1.1.1.2.25 username="admin" action="set" pathname="[system login user cctester authentication ssh-rsa /* SECRET-DATA */\]" delimiter="" value=""] User 'admin' set: [system login user cctester authentication ssh-rsa /* SECRET-DATA */] <190>1 2025-08-12T10:54:36.309Z MX480_TOE mgd 21496 UI_CMDLINE_READ_LINE [junos@2636.1.1.1.2.25 username="admin" command="set system login user cctester authentication ssh-rsa /* SECRET-DATA */ "] User 'admin', command 'set system login user cctester authentication ssh-rsa /* SECRET-DATA */ ' Ability to configure thresholds for SSH rekeying <182>1 2025-10-09T09:25:56.067Z MX480_TOE mgd 12714 UI_CFG_AUDIT_SET [junos@2636.1.1.1.2.25 username="admin" action="set" pathname="[system services ssh rekey time-limit\]" delimiter="" data="unconfigured" value="60"] User 'admin' set: [system services ssh rekey time-limit] unconfigured -- "60" <190>1 2025-10-09T09:25:56.067Z MX480_TOE mgd 12714 UI_CMDLINE_READ_LINE [junos@2636.1.1.1.2.25 username="admin" command="set system services ssh rekey time-limit 60 "] User 'admin', command 'set system services ssh rekey time-limit 60 ' <182>1 2025-10-09T09:26:20.131Z MX480_TOE mgd 12714 UI_CFG_AUDIT_SET [junos@2636.1.1.1.2.25 username="admin" action="set" pathname="[system services ssh rekey data-limit\]" delimiter="" data="unconfigured" value="15m"] User 'admin' set: [system services ssh rekey data-limit] unconfigured -- "15m" <190>1 2025-10-09T09:26:20.131Z MX480_TOE mgd 12714 UI_CMDLINE_READ_LINE [junos@2636.1.1.1.2.25 username="admin" command="set system services ssh rekey data-limit 15m "] User 'admin', command 'set system services ssh rekey data-limit 15m ' Ability to re-enable an Administrator account <190>1 2025-10-09T09:20:21.480Z MX480_TOE mgd 12714 UI_CMDLINE_READ_LINE [junos@2636.1.1.1.2.25 username="admin" command="clear system login lockout user acumensec "] User 'admin', command 'clear system login lockout user acumensec ' <37>1 2025-10-09T09:20:21.481Z MX480_TOE mgd 12714 LIBJNX_LOGIN_ACCOUNT_UNLOCKED [junos@2636.1.1.1.2.25 username="acumensec"] Account for user 'acumensec' has been unlocked for logins Ability to configure the local session inactivity time before session termination or locking <182>1 2025-08-04T10:35:29.803Z MX480_TOE mgd 71233 UI_CFG_AUDIT_SET [junos@2636.1.1.1.2.25 username="admin" action="set" pathname="[system login class security-admin idle-timeout\]" delimiter="" data="unconfigured" value="1"] User 'admin' set: [system login class security-admin idle-timeout] unconfigured -- "1" <190>1 2025-08-04T10:35:29.804Z MX480_TOE mgd 71233 UI_CMDLINE_READ_LINE [junos@2636.1.1.1.2.25 username="admin" command="set system login class security-admin idle-timeout 1 "] User 'admin', command 'set system login class security-admin idle-timeout 1 ' Ability to configure the authentication failure parameters for FIA_AFL.1 <182>1 2025-10-09T09:11:05.287Z MX480_TOE mgd 12714 UI_CFG_AUDIT_SET [junos@2636.1.1.1.2.25 username="admin" action="set" pathname="[system login retry-options tries-before-disconnect\]" delimiter="\"" data="3" value="3"] User 'admin' set: [system login retry-options tries-before-disconnect] "3 -- "3" <190>1 2025-10-09T09:11:05.288Z MX480_TOE mgd 12714 UI_CMDLINE_READ_LINE [junos@2636.1.1.1.2.25 username="admin" command="set system login retry-options tries-before-disconnect 3 "] User 'admin', command 'set system login retry-options tries-before-disconnect 3 ' <182>1 2025-10-09T09:11:23.622Z MX480_TOE mgd 12714 UI_CFG_AUDIT_SET [junos@2636.1.1.1.2.25 username="admin" action="set" pathname="[system login retry-options lockout-period\]" delimiter="\"" data="5" value="5"] User 'admin' set: [system login retry-options lockout-period] "5 -- "5" <190>1 2025-10-09T09:11:23.622Z MX480_TOE mgd 12714 UI_CMDLINE_READ_LINE [junos@2636.1.1.1.2.25 username="admin" command="set system login retry-options lockout-period 5 "] User 'admin', command 'set system login retry-options lockout-period 5 ' Ability to set the time which is used for time-stamps <190>1 2025-08-06T06:59:31.596Z MX480_TOE mgd 87699 UI_CMDLINE_READ_LINE [junos@2636.1.1.1.2.25 username="admin" command="set date 202601010808.08 "] User 'admin', command 'set date 202601010808.08 ' <190>1 2025-08-06T06:59:31.598Z MX480_TOE mgd 87699 UI_CHILD_START [junos@2636.1.1.1.2.25 command="/bin/date"] Starting child '/bin/date' <37>1 2026-01-01T08:08:08.000Z MX480_TOE date 88447 - - date set by root <190>1 2026-01-01T08:08:08.000Z MX480_TOE mgd 87699 UI_CHILD_STATUS [junos@2636.1.1.1.2.25 command="/bin/date" pid="88447" status-code="0"] Cleanup child '/bin/date', PID 88447, status 0 Ability to configure NTP <182>1 2025-07-24T10:41:28.618Z MX480_TOE mgd 21755 UI_CFG_AUDIT_OTHER [junos@2636.1.1.1.2.25 username="admin" action="set" pathname="[system ntp server 10.1.5.84\]" delimiter="" value=""] User 'admin' set: [system ntp server 10.1.5.84] <182>1 2025-07-24T10:41:28.618Z MX480_TOE mgd 21755 UI_CFG_AUDIT_SET_SECRET [junos@2636.1.1.1.2.25 username="admin" action="set" pathname="[system ntp server 10.1.5.84 key\]"] User 'admin' set: [system ntp server 10.1.5.84 key] <182>1 2025-07-24T10:41:28.618Z MX480_TOE mgd 21755 UI_CFG_AUDIT_SET [junos@2636.1.1.1.2.25 username="admin" action="set" pathname="[system ntp server 10.1.5.84 version\]" delimiter="" data="unconfigured" value="4"] User 'admin' set: [system ntp server 10.1.5.84 version] unconfigured -- "4" <190>1 2025-07-24T10:41:28.618Z MX480_TOE mgd 21755 UI_CMDLINE_READ_LINE [junos@2636.1.1.1.2.25 username="admin" command="set system ntp server 10.1.5.84 key /* SECRET-DATA */ version 4 "] User 'admin', command 'set system ntp server 10.1.5.84 key /* SECRET-DATA */ version 4 ' Ability to administer the TOE locally<37>1 2025-08-04T10:45:23.451Z MX480_TOE login 86118 - - Login attempt for user acumensec from host [unknown] <38>1 2025-08-04T10:45:27.602Z MX480_TOE login 86118 LOGIN_INFORMATION [junos@2636.1.1.1.2.25 username="acumensec" hostname="[unknown\]" tty-name="ttyu0"] User acumensec logged in from host [unknown] on device ttyu0 <190>1 2025-08-04T10:45:27.646Z MX480_TOE mgd 86163 UI_AUTH_EVENT [junos@2636.1.1.1.2.25 username="acumensec" authentication-level="j-security-admin"] Authenticated user 'acumensec' assigned to class 'j-security-admin' <190>1 2025-08-04T10:45:27.646Z MX480_TOE mgd 86163 UI_LOGIN_EVENT [junos@2636.1.1.1.2.25 username="acumensec" class-name="j-security-admin" local-peer="" pid="86163" ssh-connection="" client-mode="cli"] User 'acumensec' login, class 'j-security-admin' [86163], ssh-connection '', client-mode 'cli' Ability to manage the trusted public keys database <182>1 2025-10-09T08:56:48.726Z MX480_TOE mgd 12101 UI_CFG_AUDIT_OTHER [junos@2636.1.1.1.2.25 username="admin" action="set" pathname="[system login user cctester authentication ssh-rsa /* SECRET-DATA */\]" delimiter="" value=""] User 'admin' set: [system login user cctester authentication ssh-rsa /* SECRET-DATA */] <190>1 2025-10-09T08:56:48.726Z MX480_TOE mgd 12101 UI_CMDLINE_READ_LINE [junos@2636.1.1.1.2.25 username="admin" command="set system login user cctester authentication ssh-rsa /* SECRET-DATA */ "] User 'admin', command 'set system login user cctester authentication ssh-rsa /* SECRET-DATA */ ' |
| FMT_SMR.2 | None | None | |
| FPT_RPL.1 | Detected replay attempt | None | <27>1 2025-10-17T12:24:14.040Z MX240 secure-dot1xd 24097 DOT1XD_MKA_DUPLICATE_OR_DELAYED_PDU_DETEC TED [junos@2636.1.1.1.2.29 cak-type="PRIMARY" mka-actor="0" interface-name="ge-0/0/0"] MKA PRIMARY actor #0 received duplicate or delayed PDU on interface: ge-0/0/0 |
| FPT_SKP_EXT.1 | None | None | |
| FPT_APW_EXT.1 | None | None | |
| FPT_TST_EXT.1 | None | None | |
| FPT_TUD_EXT.1 | Initiation of update; result of the update attempt (success or failure) | None |
Initiation of update; result of the update attempt (success or failure) <190>1 2025-08-11T05:41:24.812Z MX480_TOE mgd 49536 UI_CHILD_START [junos@2636.1.1.1.2.25 command="/usr/libexec/ui/package"] Starting child '/usr/libexec/ui/package' <29>1 2025-08-11T05:41:24.814Z MX480_TOE mgd 49536 - - /usr/libexec/ui/package -X update /var/tmp/junos-vmhost-install-mx-x86-64-24.4R1.9.tgz result of the update attempt (success or failure)
** NOTE: status-code of “0”, states that the upgrade had been successful** <190>1 2025-08-11T05:41:24.812Z MX480_TOE mgd 49536 UI_CHILD_START [junos@2636.1.1.1.2.25 command="/usr/libexec/ui/package"] Starting child '/usr/libexec/ui/package' <29>1 2025-08-11T05:41:24.814Z MX480_TOE mgd 49536 - - /usr/libexec/ui/package -X update /var/tmp/junos-vmhost-install-mx-x86-64-24.4R1.9.tgz <190>1 2025-08-11T05:48:16.808Z MX480_TOE mgd 49536 UI_CHILD_STATUS [junos@2636.1.1.1.2.25 command="/usr/libexec/ui/package" pid="71662" status-code="0"] Cleanup child '/usr/libexec/ui/package', PID 71662, status 0
** NOTE: status-code other than “0”, states that the upgrade has failed** <190>1 2025-08-20T05:55:26.865Z MX480_TOE mgd 81904 UI_CHILD_START [junos@2636.1.1.1.2.25 command="/opt/support/vmhost-pkg-support"] Starting child '/opt/support/vmhost-pkg-support' <29>1 2025-08-20T05:55:26.867Z MX480_TOE mgd 81904 - - /opt/support/vmhost-pkg-support -c /var/tmp/junos-vmhost-install-mx-x86-64-24.4R1.9_modified.tgz <190>1 2025-08-20T05:56:50.618Z MX480_TOE mgd 81904 UI_CHILD_STATUS [junos@2636.1.1.1.2.25 command="/opt/support/vmhost-pkg-support" pid="82345" status-code="256"] Cleanup child '/opt/support/vmhost-pkg-support', PID 82345, status 0x100 <29>1 2025-08-20T05:56:50.618Z MX480_TOE mgd 81904 UI_CHILD_EXITED [junos@2636.1.1.1.2.25 pid="82345" return-value="1" core-dump-status="" command="/opt/support/vmhost-pkg-support"] Child exited: PID 82345, status 1, command '/opt/support/vmhost-pkg-support' |
| FPT_STM_EXT.1 | Discontinuous changes to time - either Administrator actuated or changed via an automated process | For discontinuous changes to time: The old and new values for the time. Origin of the attempt to change time for success and failure (e.g., IP address). |
Discontinuous changes to time - either Administrator actuated or changed via an automated process Admin changed time: <190>1 2025-08-06T06:59:31.596Z MX480_TOE mgd 87699 UI_CMDLINE_READ_LINE [junos@2636.1.1.1.2.25 username="admin" command="set date 202601010808.08 "] User 'admin', command 'set date 202601010808.08 ' <190>1 2025-08-06T06:59:31.598Z MX480_TOE mgd 87699 UI_CHILD_START [junos@2636.1.1.1.2.25 command="/bin/date"] Starting child '/bin/date' <37>1 2026-01-01T08:08:08.000Z MX480_TOE date 88447 - - date set by root <190>1 2026-01-01T08:08:08.000Z MX480_TOE mgd 87699 UI_CHILD_STATUS [junos@2636.1.1.1.2.25 command="/bin/date" pid="88447" status-code="0"] Cleanup child '/bin/date', PID 88447, status 0 Time change using NTP: <102>1 2025-11-07T04:29:55.044Z MX480_TOE xntpd 67284 - - kernel reports TIME_ERROR: 0x41: Clock Unsynchronized <102>1 2025-11-07T04:29:55.044Z MX480_TOE xntpd 67284 - - kernel reports TIME_ERROR: 0x41: Clock Unsynchronized <103>1 2025-11-07T04:29:55.893Z MX480_TOE xntpd 67284 - - 1 7 0 32 32 <103>1 2025-11-07T04:29:57.895Z MX480_TOE xntpd 67284 - - 1 7 0 32 32 <103>1 2025-11-07T04:29:59.895Z MX480_TOE xntpd 67284 - - 1 7 0 32 32 <103>1 2025-11-07T04:30:01.898Z MX480_TOE xntpd 67284 - - 1 7 0 32 32 <14>1 2025-11-07T07:05:24.906Z MX480_TOE xntpd - NTPD_CHANGED_TIME [junos@2636.1.1.1.2.25 rate="9323.007043"] time reset +9323.007043 s <101>1 2025-11-07T07:05:24.906Z MX480_TOE xntpd 67284 - - ntpd: time reset +9323.007043 s admin@MX480_TOE:fips> show ntp associations remote refid auth st t when poll reach delay offset jitter rootdelay rootdisp ===================================================================================================================== *10.1.5.97 96.231.54.40 SKEY 2 u 22 64 3 0.451 -0.113 0.139 8.362 27.054
admin@MX480_TOE:fips>
|
| FTA_SSL.3 | The termination of a remote session by the session locking mechanism | None |
The termination of a remote session by the session locking mechanism <14>1 2025-08-04T11:48:37.181Z MX480_TOE -cli - UI_CLI_IDLE_TIMEOUT [junos@2636.1.1.1.2.25 username="acumensec"] Idle timeout for user 'acumensec' exceeded and session terminated <190>1 2025-08-04T11:48:37.181Z MX480_TOE mgd 89124 UI_LOGOUT_EVENT [junos@2636.1.1.1.2.25 username="acumensec"] User 'acumensec' logout <38>1 2025-08-04T11:48:37.183Z MX480_TOE sshd 89122 - - Received disconnect from 10.1.5.84 port 50294:11: disconnected by user <38>1 2025-08-04T11:48:37.183Z MX480_TOE sshd 89122 - - Disconnected from user acumensec 10.1.5.84 port 50294 |
| FTA_SSL.4 | The termination of an interactive session | None |
The termination of an interactive session <190>1 2025-08-04T09:45:46.370Z MX480_TOE mgd 83269 UI_CMDLINE_READ_LINE [junos@2636.1.1.1.2.25 username="acumensec" command="exit "] User 'acumensec', command 'exit ' <190>1 2025-08-04T09:45:46.370Z MX480_TOE mgd 83269 UI_LOGOUT_EVENT [junos@2636.1.1.1.2.25 username="acumensec"] User 'acumensec' logout |
| FTA_SSL_EXT.1 (if “terminate the session” is selected) | The termination of a local session by the session locking mechanism | None |
The termination of a local session by the session locking mechanism <14>1 2025-08-04T10:46:32.246Z MX480_TOE -cli - UI_CLI_IDLE_TIMEOUT [junos@2636.1.1.1.2.25 username="acumensec"] Idle timeout for user 'acumensec' exceeded and session terminated <190>1 2025-08-04T10:46:32.247Z MX480_TOE mgd 86163 UI_LOGOUT_EVENT [junos@2636.1.1.1.2.25 username="acumensec"] User 'acumensec' logout |
| FTA_TAB.1 | None | None | |
| FTP_ITC.1 |
|
|
<38>1 2025-10-09T08:21:56.548Z MX480_TOE sshd 11107 - - Accepted publickey for syslog-mon from 10.1.5.84 port 49514 ssh2: ECDSA SHA256:nh0jpMNtA7wsC1Cti+f/VEFD8CjkZvsn+Qi1UDwt7LM <190>1 2025-10-09T08:21:56.640Z MX480_TOE mgd 11111 UI_AUTH_EVENT [junos@2636.1.1.1.2.25 username="syslog-mon" authentication-level="j-monitor"] Authenticated user 'syslog-mon' assigned to class 'j-monitor' <190>1 2025-10-09T08:21:56.641Z MX480_TOE mgd 11111 UI_LOGIN_EVENT [junos@2636.1.1.1.2.25 username="syslog-mon" class-name="j-monitor" local-peer="" pid="11111" ssh-connection="10.1.5.84 49514 10.1.2.158 22" client-mode="cli"] User 'syslog-mon' login, class 'j-monitor' [11111], ssh-connection '10.1.5.84 49514 10.1.2.158 22', client-mode 'cli'
<30>1 2025-10-09T08:27:14.238Z MX480_TOE mgd 11110 UI_NETCONF_MONITORING_DELETE [junos@2636.1.1.1.2.25 message="11110"] Netconf session with pid '11110' is being deleted <190>1 2025-10-09T08:27:14.247Z MX480_TOE mgd 11110 UI_LOGOUT_EVENT [junos@2636.1.1.1.2.25 username="syslog-mon"] User 'syslog-mon' logout
<38>1 2025-10-09T08:36:32.385Z MX480_TOE sshd 11646 - - Unable to negotiate with 10.1.5.84 port 47950: no matching MAC found. Their offer: hmac-md5 [preauth] |
| FTP_TRP.1/Admin |
|
|
<38>1 2025-07-09T12:06:43.690Z MX480_TOE sshd 23064 - - Accepted keyboard-interactive/pam for acumensec from 10.1.5.84 port 35624 ssh2 <190>1 2025-07-09T12:06:43.780Z MX480_TOE mgd 23070 UI_AUTH_EVENT [junos@2636.1.1.1.2.25 username="acumensec" authentication-level="j-security-admin"] Authenticated user 'acumensec' assigned to class 'j-security-admin' <190>1 2025-07-09T12:06:43.780Z MX480_TOE mgd 23070 UI_LOGIN_EVENT [junos@2636.1.1.1.2.25 username="acumensec" class-name="j-security-admin" local-peer="" pid="23070" ssh-connection="10.1.5.84 35624 10.1.2.158 22" client-mode="cli"] User 'acumensec' login, class 'j-security-admin' [23070], ssh-connection '10.1.5.84 35624 10.1.2.158 22', client-mode 'cli'
<38>1 2025-07-09T12:08:55.986Z MX480_TOE sshd 23068 - - Received disconnect from 10.1.5.84 port 35624:11: disconnected by user <38>1 2025-07-09T12:08:55.986Z MX480_TOE sshd 23068 - - Disconnected from user acumensec 10.1.5.84 port 35624
<38>1 2025-08-12T11:53:11.090Z MX480_TOE sshd 30530 - - Unable to negotiate with 10.1.2.65 port 49874: no matching cipher found. Their offer: aes192-ctr [preauth] |
In addition, Juniper Networks recommends:
-
To capture all changes to the configuration.
-
To store logging information remotely.
For more information on log details, see Specifying Log File Size, Number, and Archiving Properties