Configure Audit Log Options in FIPS Mode
Learn to configure audit log options in FIPS mode.
Configure Audit Log Options on Your Device in FIPS Mode
Only authenticated administrators are authorized to delete locally stored audit data.
To configure audit log options:
Junos OS Log File Management and Storage Behavior
The Junos OS maintains logs through active log file and a set of archived log files (10 files by default, but configurable 1 through 1000 files). When the active file log reaches its maximum file size (1 GB by default, but configurable 65536 to 1073741824 bytes, that is 64 KB to 1 GB), the login utility performs the following steps:
Archiving the Active File:
When the active log file reaches its maximum size the logging utility:
Closes and compresses the log file
Saves the file as
logfile.0.gz.Creates an active log file for ongoing logging.
Managing Older Archives:
When the new active file log reaches the maximum size, the existing
logfile.0.gzis renamed tologfile.1.gz.The current active log file is then closed, compressed, and renamed to
logfile.0.gz.
Managing Archive Limits:
When the maximum number of archived files is reached and the active log file reaches its size limit, the oldest archived file is deleted.
This ensures space for the newest archive file while maintaining the configured number of backups.
Storage Management for Syslog Files
A 1 GB syslog file takes approximately 0.25 GB of storage when archived. Syslog
files can consume all allocated storage in to /var file, which
is platform specific.
When the filesystem reaches 92% storage capacity an event is raised to the administrator. However, the event process continues using the reserved storage blocks to ensure uninterrupted logging till the administrator frees the storage.
Storage Exhaustion Management
When the /var file storage exhausted, the system logs a final
entry reporting No space left on device and terminates the
logging. The appliance continues to operate in the event of exhaustion of audit
log storage space.
Sample Code Audits of Configuration Changes
This sample code audits all changes to the configuration secret data and sends the logs to a file named Audit-File:
[edit system]
syslog {
file Audit-File {
authorization info;
change-log info;
interactive-commands info;
}
}
This sample code expands the scope of the minimum audit to audit all changes to the configuration, not just secret data, and sends the logs to a file named Audit-File:
[edit system]
syslog {
file Audit-File {
any any;
authorization info;
change-log any;
interactive-commands info;
kernel info;
pfe info;
}
}
Example: The System Logging of Configuration Changes
This example shows a sample configuration and makes changes to users and secret
data. It then shows the information sent to the audit server when the secret
data is added to the original configuration and committed with the
load command.
[edit system]
location {
country-code US;
building B1;
}
...
login {
message "UNAUTHORIZED USE OF THIS ROUTER\n\tIS STRICTLY PROHIBITED!";
user admin {
uid 2000;
class super-user;
authentication {
encrypted-password “$ABC123”;
# SECRET-DATA
}
}
}
radius-server 192.0.2.15 {
secret “$ABC123” # SECRET-DATA
}
services {
ssh;
}
syslog {
user *{
any emergency;
}
file messages {
any notice;
authorization info;
}
file interactive-commands {
interactive-commands any;
}
}
...
...
The new configuration changes the secret data configuration statements and adds a new user.
security-administrator@host:fips# show | compare
[edit system login user admin authentication]
– encrypted-password “$ABC123”; # SECRET-DATA
+ encrypted-password “$ABC123”; # SECRET-DATA
[edit system login]
+ user admin2 {
+ uid 2001;
+ class operator;
+ authentication {
+ encrypted-password “$ABC123”;
# SECRET-DATA
+ }
+ }
[edit system radius-server 192.0.2.15]
– secret “$ABC123”; # SECRET-DATA
+ secret “$ABC123”; # SECRET-DATA