User's Manual

Table Of Contents
Fortress ES-Series CLI Guide: Network Security, Authentication and Auditing
170
Configure global audit logging of administrative activity
interactively with
set audit:
Alternatively, you can execute
set audit
non-interactively with
valid switches and arguments in any order and combination:
# set audit -login enable|disable -security enable|disable -configuration enable|disable
-GUI required|prohibited|automatic -SSH required|prohibited|automatic
-SNMP required|prohibited|automatic -console required|prohibited|automatic
-wired required|prohibited|automatic -wireless required|prohibited|automatic
-encryptedzone required|prohibited|automatic -clearzone required|prohibited|automatic
NOTE: Additional
switches to config-
ure learned device
auditing with set
audit are covered in
Section 4.7.4.
The Mesh Point CLI returns [OK] when settings are
successfully set.
You must be logged on to an
administrator
-level account to
configure audit logging (refer to Section 2.2).
4.7.3 Auditing and Filtering Administrative
Activity by MAC Address
You can specify MAC addresses for audit logging of
administrative activity and filter audit events by interface and
zone.
Audit logging settings for specified MAC addresses override
global auditing settings for administrative activity (Section
4.7.2). However, the
-audit settings of individual
administrative accounts (Section 2.2.3), override MAC-address
auditing.
View current MAC-address auditing settings with
show
macaudit
:
# show macaudit -all
MAC Address Description Gui Ssh Snmp Wired Wireless Clear Zone Encrypted Zone
----------- ----------- --- --- ---- ----- -------- ---------- --------------
By default, no MAC addresses are specified for auditing.
#
set audit
Login[enable] (enable|disable to enable or disable auditing of logins):
Security[enable] (enable|disable to enable or disable auditing of security events):
Configuration[enable] (enable|disable to enable or disable auditing of configuration events):
GUI[required] (required | prohibited | automatic to enable or disable auditing of events from the GUI):
SSH[required] (required | prohibited | automatic to enable or disable auditing of events from access via SSH):
SNMP[required] (required | prohibited | automatic to enable or disable auditing of events from access via SNMP):
Console[required] (required | prohibited | automatic to enable or disable auditing of events from access via the console):
Wired[required] (required | prohibited | automatic to enable or disable auditing of events from access via wired interfaces):
Wireless[required] (required | prohibited | automatic to enable or disable auditing of events from access via wireless interfaces):
Clear Zone[required] (required | prohibited | automatic to enable or disable auditing of events from access via the clear zone):
Encrypted Zone[required] (required | prohibited | automatic to enable or disable auditing of events from access via the encrypted zone):
Learned Wired[enable] (enable|disable to enable or disable auditing of learned wired activity):
Learned Wireless[enable] (enable|disable to enable or disable auditing of learned wireless activity):
Learned Encrypted[enable] (enable|disable to enable or disable auditing of learned wireless activity):
Learned Clear[enable] (enable|disable to enable or disable auditing of learned wireless activity):