1.11.2 Configure syslog-client to log using TLS

Information

Logging to a remote syslog server should be configured to use TLS and include auditable events.

Logging to a remote syslog server offers several advantages, including centralized log management, improved security, long-term data retention, and enhanced troubleshooting capabilities. By consolidating logs from various devices into a single location, administrators can easily monitor, analyze, and respond to issues across the network.

Solution

Configure the switch to send logs to a syslog-server using tls on the mgmt VRF and include auditable events.

logging <SYSLOG-SERVER> tls <PORT> auth-mode subject-name vrf mgmt include-auditable-events

Impact:

Without a centralized logging location, logs on the switch may roll over and be lost.

See Also

https://workbench.cisecurity.org/benchmarks/24202

Item Details

Category: ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AC-17(2), 800-53|AU-2, 800-53|AU-3, 800-53|AU-3(1), 800-53|AU-7, 800-53|AU-12, 800-53|IA-5, 800-53|IA-5(1), 800-53|SC-8, 800-53|SC-8(1), CSCv7|6.2, CSCv7|6.3, CSCv7|14.4

Plugin: ArubaOS

Control ID: 83fa4baaed8c9980b6632ebcbbbfa69c71681d59a1dd4c9efd54589e5f784db7