User's Manual

Table Of Contents
Fortress ES-Series CLI Guide: Network Security, Authentication and Auditing
172
You can delete a specified MAC address or all MAC addresses
currently configured for administrator audit logging with the
del
command:
# del macaudit -mac
<MACaddress>
|all
You must be logged on to an
administrator
-level account to
configure audit logging (refer to Section 2.2).
4.7.4 Filtering Audited Learned-Device Activity
When remote audit logging is enabled (Section 4.7.1), you can
filter audit logging of events generated by devices connecting
to the Mesh Point-secured network by interface and zone
(encrypted and clear).
View the current settings for audit logging of learned device
activity in the last four lines of
show audit output:
NOTE: Learned-
device audit log-
ging is viewed and con-
figured through the
same command options
as global administrator
audit logging, which is
covered in Section 4.7.2.
# show audit
Audit Settings
--------------
Login: enable
Security: enable
configuration: enable
GUI: required
SSH: required
SNMP: required
Console: required
Wired: required
Wireless: required
Clear Zone: required
Encrypted Zone: required
Learned Wired: enable
Learned Wireless: enable
Learned Encrypted: enable
Learned Clear: enable
You can filter audit-log events associated with connecting
devices by the types of interfaces they can connect to (wired
and wireless) and the zones they can connect from (encrypted
and clear). When audit logging for these parameters are set to
enable
(the default), events of that type are sent to the audit
log. When they are set to
disable
, corresponding events are
not sent.