User's Manual

Table Of Contents
Fortress ES-Series CLI Guide: Network Security, Authentication and Auditing
169
4.7.3). An individual account or MAC address auditing setting
of
required
or
prohibited
overrides global audit logging
settings.
NOTE: Adminis-
trator audit log-
ging is viewed and
configured through the
same command options
as learned-device audit
logging, which is cov-
ered in Section 4.7.4.
View the current global settings for administrative activity audit
logging with
show audit:
# show audit
Audit Settings
--------------
Login: enable
Security: enable
Configuration: enable
GUI: required
SSH: required
SNMP: required
Console: required
Wired: required
Wireless: required
Clear Zone: required
Encrypted Zone: required
Learned Wired: enable
Learned Wireless: enable
Learned Encrypted: enable
Learned Clear: enable
NOTE: On Mesh
Points without
radios, Wireless inter-
faces and related audit
logging controls are
absent.
You can globally filter audit logging of administrative activity by
event type. When
Login, Security and/or Configuration are
set to
enable
(the default), events of that type are sent to the
audit log. When any of these event types are set to
disable
,
corresponding events are not sent.
You can also globally filter audit logging of administrative
activity based on:
1 the management interfaces administrators use to access
the Mesh Point:
GUI, SSH, SNMP, Console
2 the zones administrators connect from: Clear Zone,
Encrypted Zone
3 the physical interfaces administrators connect through:
Wired, Wireless
Because any given administrative session can be defined by
more than one of the above parameters, they are used
hierarchically, in the order given above, to determine whether
an event will be audited:
NOTE: The
Learned device
parameters returned by
show audit are cov-
ered in Section 4.7.4.
Each of these administrator interface and zone parameters can
cause a given event be
required
(the default) for auditing or
prohibited
from auditing, and the first such “hard” setting in the
hierarchy of audit parameters determines whether or not an
event is forwarded to the audit log. Alternatively, auditing can
be set to
automatic
for any parameter, which allows an inferior
setting in the hierarchy to determine audit behavior.