SV-101209r1_rule
V-91109
SRG-APP-000080-NDM-000220
JUNI-ND-000210
CAT II
10
Configure the router to log configuration changes as shown in the following example:
set syslog file LOG_FILE change-log info
Note: The parameter “any” can be in place of “change-log” as this will log everything. Also, a syslog server can be configured in addition to or in lieu of logging to a file as shown in the example below.
set syslog host 10.1.58.2 any info
Review the router configuration to determine if it logs configuration changes as shown in the following example:
system {
syslog {
file LOG_FILE {
change-log info;
}
}
}
Note: The parameter “any” can be in place of “change-log” as this will log everything. Also, a syslog server can be configured in addition to or in lieu of logging to a file as shown in the example below.
system {
syslog {
host 10.1.58.2 {
any info;
}
file LOG_FILE {
change-log info;
}
console {
any error;
}
}
}
If configuration change activity is not logged, this is a finding.
V-91109
False
JUNI-ND-000210
Review the router configuration to determine if it logs configuration changes as shown in the following example:
system {
syslog {
file LOG_FILE {
change-log info;
}
}
}
Note: The parameter “any” can be in place of “change-log” as this will log everything. Also, a syslog server can be configured in addition to or in lieu of logging to a file as shown in the example below.
system {
syslog {
host 10.1.58.2 {
any info;
}
file LOG_FILE {
change-log info;
}
console {
any error;
}
}
}
If configuration change activity is not logged, this is a finding.
M
3381