SV-75295r1_rule
V-60839
SRG-APP-000028-NDM-000210
AMLS-NM-000140
CAT II
10
Enable logging on the switch with sufficient detail to fulfill the specifications set forth in the VulDiscussion.
To configure logging to a remote syslog server at the informational level, enter:
switch#config
switch(config)#logging host [ip address]
switch(config)#logging trap informational
Then configure the following AAA
aaa accounting commands all default start-stop logging [group radius]
Review the switch configuration and verify that logging is enabled.
If logging is not enabled or is not enabled with sufficient detail to fulfill the specifications set forth in the VulDiscussion, this is a finding.
To determine if logging is enabled, enter:
switch#show logging
The output must show logging as enabled, with a logging level of informational or debugging.
In order to ensure all user commands are captured, the following statement must be in the running config.
aaa accounting commands all default start-stop logging [group radius]
V-60839
False
AMLS-NM-000140
Review the switch configuration and verify that logging is enabled.
If logging is not enabled or is not enabled with sufficient detail to fulfill the specifications set forth in the VulDiscussion, this is a finding.
To determine if logging is enabled, enter:
switch#show logging
The output must show logging as enabled, with a logging level of informational or debugging.
In order to ensure all user commands are captured, the following statement must be in the running config.
aaa accounting commands all default start-stop logging [group radius]
M
2825