[j-nsp] Strange Behavior

Adnan Mohsin adnanmohsin at yahoo.com
Mon Dec 7 05:00:47 EST 2009





 

Hi,

 

I
observed strange behavior today with one of my Juniper router. When ever i do show
| compare rollback on juniper router, I receive some unexpected output
of commands on my TACACS# server and also on messages file on juniper router.
The output I receive on TACACS server and messages file is related to
authenticaton i.e OSPF authentication , root-authentication and users
authentication. I observed this behavior first time. Can any body tell me why i
am getting these strange output in my logs? did any body else observed the
same behavior before?

 

Following
is a output from TACACS# server.

 

Mon
Dec  7 07:31:18 2009         
cmd=show | compare rollback 0 <cr>

Mon Dec  7 07:31:19 2009       
xxx.xxx.xxx.xxx    ttyp0   
stop    task_id=223    
service=shell   process*mgd[8696]   cmd=set: [system
root-authentication encrypted-password]

Mon Dec  7 07:31:19 2009       
xxx.xxx.xxx.xxx   ttyp0    stop   
task_id=224     service=shell  
process*mgd[8696]   cmd=deactivate: [system root-authentication
encrypted-password] ""

Mon Dec  7 07:31:19 2009       
xxx.xxx.xxx.xxx    ttyp0   
stop    task_id=225    
service=shell   process*mgd[8696]   cmd=set: [system
tacplus-server xx.xx.xx.xx secret]

Mon Dec  7 07:31:19 2009       
xxx.xxx.xxx.xxx    ttyp0   
stop    task_id=226    
service=shell   process*mgd[8696]   cmd=deactivate: [system
tacplus-server xx.xx.xx.xx secret] ""

Mon Dec  7 07:31:19 2009        xxx.xxx.xxx.xxx   
ttyp0    stop   
task_id=227     service=shell  
process*mgd[8696]   cmd=set: [system accounting destination tacplus
server xx.xx.xx.xx secret]

Mon Dec  7 07:31:19 2009       
xxx.xxx.xxx.xxx    ttyp0   
stop    task_id=228     service=shell  
process*mgd[8696]   cmd=deactivate: [system accounting destination
tacplus server xx.xx.xx.xx secret] ""

Mon Dec  7 07:31:19 2009       
xxx.xxx.xxx.xxx    ttyp0   
stop    task_id=233    
service=shell   process*mgd[8696]   cmd=set: [system login
user xxxxx authentication encrypted-password]

Mon Dec  7 07:31:19 2009       
xxx.xxx.xxx.xxx    ttyp0   
stop    task_id=234    
service=shell   process*mgd[8696]   cmd=deactivate: [system
login user xxxxx authentication encrypted-password] ""

Mon Dec  7 07:31:19 2009       
xxx.xxx.xxx.xxx    ttyp0   
stop    task_id=235    
service=shell   process*mgd[8696]   cmd=set: [protocols
ospf area xx.xx.xx.xx interface e1-0/0/2.0 authentication md5 100 key]

Mon Dec  7 07:31:19 2009       
xxx.xxx.xxx.xxx   ttyp0    stop   
task_id=236     service=shell  
process*mgd[8696]   cmd=deactivate: [protocols ospf area xx.xx.xx.xx
interface e1-0/0/2.0 authentication md5 100 key] ""

 

Router
messages file output

 

Dec 
7 14:44:09   mgd[9362]: %CHANGE-6-UI_CFG_AUDIT_SET_SECRET: User
'xxxxx' set: [system root-authentication encrypted-password]

Dec  7 14:44:09   mgd[9362]: %CHANGE-6-UI_CFG_AUDIT_OTHER: User
'xxxxxx' deactivate: [system root-authentication encrypted-password]
""

Dec  7 14:44:09   mgd[9362]: %CHANGE-6-UI_CFG_AUDIT_SET_SECRET:
User 'xxxxxx' set: [system tacplus-server xx.xx.xx.xx secret]

Dec  7 14:44:09   mgd[9362]: %CHANGE-6-UI_CFG_AUDIT_OTHER: User
'xxxxxx' deactivate: [system tacplus-server xx.xx.xx.xx secret] ""

Dec  7 14:44:09   mgd[9362]: %CHANGE-6-UI_CFG_AUDIT_SET_SECRET:
User 'xxxxxx' set: [system accounting destination tacplus server xx.xx.xx.xx
secret]

Dec  7 14:44:09   mgd[9362]: %CHANGE-6-UI_CFG_AUDIT_OTHER: User
'xxxxxx' deactivate: [system accounting destination tacplus server xx.xx.xx.xx
secret] ""

Dec  7 14:44:09   mgd[9362]: %CHANGE-6-UI_CFG_AUDIT_SET_SECRET:
User 'xxxxxx' set: [system login user xxxxx authentication encrypted-password]

Dec  7 14:44:09   mgd[9362]: %CHANGE-6-UI_CFG_AUDIT_OTHER: User
'xxxxxx' deactivate: [system login user xxxxx authentication
encrypted-password] ""

Dec  7 14:44:09   mgd[9362]: %CHANGE-6-UI_CFG_AUDIT_SET_SECRET:
User 'xxxxxx' set: [protocols ospf area xx.xx.xx.xx interface e1-0/0/2.0
authentication md5 100 key]

Dec  7 14:44:09   mgd[9362]: %CHANGE-6-UI_CFG_AUDIT_OTHER: User
'xxxxxx' deactivate: [protocols ospf area xx.xx.xx.xx interface e1-0/0/2.0
authentication md5 100 key] ""

 

Any
help would be really appreciated.
thanks.Adnan.





      


More information about the juniper-nsp mailing list