Hi once again, so I have set up Kiwi syslog on the server, and its monitering, I have used:
security authentication failure rate 2 log
logging userinfo
logging buffered 51200 warnings
no logging console
no logging monitor
However I cant see the login fails in the log, only the successful logins?
Thanks for all the replys, I found a useful link also that has helped with this:
http://www.ciscozine.com/2009/04/16/tips-for-securing-cisco-administrative-access/
No TACACS+, the router itself was setup for vpn access(1841 series)I used the clear line vty command to remove the user few hours ago seems to be OK for now...or until they try again!
Hi all, looking for a little help and advice, a router seems to be under attack, seems to be a brute force attack as I can see several usernames trying to logon such as: test, root, admin, server etc the ip address has changed since yesterday and seems to be spoofed.US & NL
Is there a way that...
Here is the config, if you can spot the issue would be great:
Company1>en
Password:
Company1#sh run
Building configuration...
Current configuration : 7197 bytes
!
version 12.4
service timestamps debug datetime msec
service timestamps log datetime msec
service password-encryption
!
hostname...
I'm not sure I can do this, when the issue first came up as the user being unable to get mail, I looked into this for some time and the solution was to place the DNS settings in the client and it worked.
I'm aware that the config would help with this put seeing as its a large company posting up...
Hi All, I have a cisco vpn set up, all is working well besides one issue, in order to work with exchange server I need to enter the dns settings into the networking connection settings, once the connection is closed the dns settings are lost, meaning that the have to be entered eacj time the...
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.