Review audit events

Review these examples of audit events and records that appear in Common Criteria evaluated configuration.

The record contents are shown in McAfee ESM format. To set the format to use, see the Add rules for forwarding audit data from Management Servers topic in the Reconfiguring the SMC and Security Engines chapter in the Forcepoint Network Security Platform Product Guide. Some of the more common McAfee ESM fields are described in the following table.

Field Description
Timestamp Log entry creation time.
NodeId IP address of the engine or server that sent the log entry.
Facility The engine subsystem that created the log entry.
CompId The identifier of the creator of the log entry.
InfoMsg A description of the log event that further explains the entry.
SenderType The type of engine or server that sent the log entry.
EventId Event identifier, unique within one sender.
UserOriginator Administrator who triggered the audit event.
ClientIpAddress Address of the client that triggered the audit event.
Type Log entry severity type.
TypeDescription Type of action that triggered the audit entry.
Result Result state after the audited event.
ObjectName Elements being manipulated in the audit event.
SituationId The identifier of the situation that triggered the log event.
Situation Situation name.
Note: The SenderType field contains "Management Server", "Log Server", or "Engine" for Management Server, Log Server, and Security Engine, respectively, and the NodeId contains the IP address of the sender. The SMC Appliance syslogs are sent from a loopback address and include the hostname of the Virtual SMC Appliance after the timestamp of the syslog message.
FAU_GEN.1.1 a)
Auditable event Start up and shutdown of the audit functions.
Startup of SMC Appliance

Timestamp="2025-03-17 16:45:35",
NodeId="192.0.2.2",
CompId="Management Server",
SenderType="Management Server",
EventId="2665877378764374017",
UserOriginator="System",
ClientIpAddress="192.0.2.2",
TypeDescription="audit.start",
Result="Success",
ObjectName="Audit function started"
Timestamp="2025-03-17 16:47:09",
NodeId="192.0.2.2",
CompId="LogServer 192.0.2.2",
SenderType="Log Server",
EventId="2666279465012690945",
UserOriginator="System",
ClientIpAddress="192.0.2.2",
TypeDescription="audit.start",
Result="Success",
ObjectName="Audit function started"

Shutdown of SMC Appliance

Timestamp="2025-03-17 16:48:58",
NodeId="192.0.2.2",
CompId="Management Server",
SenderType="Management Server",
EventId="2665770623057264758",
UserOriginator="System",
ClientIpAddress="192.0.2.2",
TypeDescription="audit.stop",
Result="Success",
ObjectName="Audit function shutdown"
Timestamp="2025-03-17 16:51:14",
NodeId="192.0.2.2",
CompId="LogServer 192.0.2.2",
SenderType="Log Server",
EventId="2666399363319726188",
UserOriginator="System",
ClientIpAddress="192.0.2.2",
TypeDescription="audit.stop",
Result="Success",
ObjectName="Audit function shutdown"

Startup of Security Engine

Timestamp="2025-03-17 16:44:28",
LogId="1803",
NodeId="192.0.2.4",
Facility="System Utilities",
Type="Notification",
CompId="ngfw node 1",
InfoMsg="Auditing log start",
ReceptionTime="2025-03-17 16:47:21",
SenderType="Firewall",
SituationId="78022",
Situation="System_Engine-Log-Auditing-State",
EventId="7307441706553575179"

Shutdown of Security Engine

Timestamp="2025-03-17 16:43:11",
LogId="1763",
NodeId="192.0.2.4",
Facility="Management",
Type="Notification",
CompId="ngfw node 1",
InfoMsg="Auditing log end",
ReceptionTime="2025-03-17 16:44:29",
SenderType="Firewall",
SituationId="78022",
Situation="System_Engine-Log-Auditing-State",
EventId="7307441384431027939"

FAU_GEN.1.1 c)
Auditable event Administrative login and logout
Administrative login

Timestamp="2025-03-17 16:48:05",
NodeId="192.0.2.2",
CompId="Management Server",
InfoMsg="Login succeeded for user test00 in domain Shared Domain",
SenderType="Management Server",
EventId="2665877378764374111",
UserOriginator="System",
ClientIpAddress="192.0.2.1",
TypeDescription="stonegate.admin.login",
Result="Success",
ObjectName="test00;Shared Domain"

Administrative logout

Timestamp="2025-03-17 16:51:29",
NodeId="192.0.2.2",
CompId="Management Server",
InfoMsg="Logout succeeded for user test00.",
SenderType="Management Server",
EventId="2666836548040786018",
UserOriginator="System",
ClientIpAddress="127.0.0.1",
TypeDescription="stonegate.admin.logout",
Result="Success",
ObjectName="test00"

Table 1.
FMT_SMF.1, FAU_GEN.1.1 c)
Auditable event Security related configuration changes
Audit server configuration changes

Timestamp="2025-04-01 17:18:27",
NodeId="192.0.2.2",
CompId="Management Server",
InfoMsg="A new log forward rule was created with All Log Data types to host syslog_server (port 2055).",
SenderType="Management Server",
EventId="8239535049569992843",
UserOriginator="test00",
ClientIpAddress="192.0.2.1",
TypeDescription="stonegate.log.forward.new",
Result="Success",
ObjectName="Management Server"
Timestamp="2025-04-01 17:18:27",
NodeId="192.0.2.2",
CompId="Management Server",
InfoMsg="A log forward rule was deleted.",
SenderType="Management Server",
EventId="8239535049569992844",
UserOriginator="test00",
ClientIpAddress="192.0.2.1",
TypeDescription="stonegate.log.forward.deleted",
Result="Success",
ObjectName="Management Server"

Configuring reference identifier for the peer

Timestamp="2025-02-14 13:40:53",
NodeId="192.0.2.2",
CompId="Management Server",
InfoMsg="netflow_collector has been added: <netflow_collector data_context='All Log Data' netflow_collector_host_ref='syslog_server' netflow_collector_port='2055' netflow_collector_service='tcp_with_tls' netflow_collector_version='esm' tls_profile='Syslog TLS profile'/>.",
SenderType="Management Server",
EventId="337242339615441298",
UserOriginator="test00",
ClientIpAddress="192.0.2.1",
TypeDescription="stonegate.object.update.details",
Result="Success",
ObjectName="Management Server"

Modification of administrator accounts

Timestamp="2025-02-27 11:39:05",
NodeId="192.0.2.2",
CompId="cc-smca-mgmt",
SenderType="Management Server",
EventId="2575083827416278967",
UserOriginator="radmin",
ClientIpAddress="192.168.200.1",
TypeDescription="stonegate.admin.enginepassword.change",
Result="Success",
ObjectName="smcadmin"
Timestamp="2025-02-27 11:39:05",
NodeId="192.0.2.2",
CompId="cc-smca-mgmt",
SenderType="Management Server",
EventId="2575083827416278966",
UserOriginator="radmin",
ClientIpAddress="192.168.200.1",
TypeDescription="stonegate.admin.password.change",
Result="Success",
ObjectName="smcadmin"
Timestamp="2025-02-27 11:39:05",
NodeId="192.0.2.2",
CompId="cc-smca-mgmt",
SenderType="Management Server",
EventId="2575083827416278965",
UserOriginator="radmin",
ClientIpAddress="192.168.200.1",
TypeDescription="stonegate.object.insert",
Result="Success",
ObjectName="smcadmin"
Timestamp="2025-02-27 11:41:15",
NodeId="192.0.2.2",
CompId="cc-smca-mgmt",
InfoMsg="Administrator has changed for Restricted permissions.",
SenderType="Management Server",
EventId="2575083827416288532",
UserOriginator="radmin",
ClientIpAddress="192.168.200.1",
TypeDescription="stonegate.admin.permission.change",
Result="Success",
ObjectName="smcadmin"
Timestamp="2025-02-27 11:43:44",
NodeId="192.0.2.2",
CompId="cc-smca-mgmt",
InfoMsg="Administrator has changed for Unrestricted permissions.",
SenderType="Management Server",
EventId="2575083827416288537",
UserOriginator="radmin",
ClientIpAddress="192.168.200.1",
TypeDescription="stonegate.admin.permission.change",
Result="Success",
ObjectName="smcadmin"

Modification of administrator accounts

(Continued)

Timestamp="2025-02-27 11:43:44",
NodeId="192.0.2.2",
CompId="cc-smca-mgmt",
SenderType="Management Server",
EventId="2575083827416288538",
UserOriginator="radmin",
ClientIpAddress="192.168.200.1",
TypeDescription="stonegate.object.update",
Result="Success",
ObjectName="smcadmin"

Logon banner change

Timestamp="2025-02-27 11:47:36",
NodeId="192.0.2.2",
CompId="cc-smca-mgmt",
InfoMsg="Updated Global System Property logon_banner_text to This is CC Audit Log Lab SMC running in FIPS mode.Unauthorized Access Prohibited. Copyright (c) 2025 Forcepoint.",
SenderType="Management Server",
EventId="2575083827416288550",
UserOriginator="radmin",
ClientIpAddress="192.168.200.1",
TypeDescription="stonegate.object.update",
Result="Success",
ObjectName="logon_banner_text"

Minimum password length

Timestamp="2025-02-27 11:52:06",
NodeId="192.0.2.2",
CompId="cc-smca-mgmt",
InfoMsg="Updated Global System Property password_character_number_minimum to 12",
SenderType="Management Server",
EventId="2575083827416288557",
UserOriginator="radmin",
ClientIpAddress="192.168.200.1",
TypeDescription="stonegate.object.update",
Result="Success",
ObjectName="password_character_number_minimum"

Remote session timeout change

Timestamp="2025-02-27 11:58:07",
NodeId="192.0.2.2",
CompId="cc-smca-mgmt",
InfoMsg="Updated Global System Property gui_inactivity_max_in_min to 15",
SenderType="Management Server",
EventId="2575083827416288559",
UserOriginator="radmin",
ClientIpAddress="192.168.200.1",
TypeDescription="stonegate.object.update",
Result="Success",
ObjectName="gui_inactivity_max_in_min"
Timestamp="2025-02-27 11:59:32",
NodeId="192.0.2.2",
CompId="cc-smca-mgmt",
InfoMsg="Updated Global System Property behavior_after_reach_gui_inactivity_max to TERMINATE_SESSION",
SenderType="Management Server",
EventId="2575083827416288561",
UserOriginator="radmin",
ClientIpAddress="192.168.200.1",
TypeDescription="stonegate.object.update",
Result="Success",
ObjectName="behavior_after_reach_gui_inactivity_max"

Configure authentication failure parameters for FIA_AFL.1

Timestamp="2025-02-27 12:21:33",
NodeId="192.0.2.2",
CompId="cc-smca-mgmt",
InfoMsg="Updated Global System Property conf_time_login_delayed to 30",
SenderType="Management Server",
EventId="2575083827416288590",
UserOriginator="radmin",
ClientIpAddress="192.168.200.1",
TypeDescription="stonegate.object.update",
Result="Success",
ObjectName="conf_time_login_delayed"
Timestamp="2025-02-27 12:21:33",
NodeId="192.0.2.2",
CompId="cc-smca-mgmt",
InfoMsg="Created Global System Property failed_login_max_before_lockout with values 10",
SenderType="Management Server",
EventId="2575083827416288592",
UserOriginator="radmin",
ClientIpAddress="192.168.200.1",
TypeDescription="stonegate.object.insert",
Result="Success",
ObjectName="failed_login_max_before_lockout"
Timestamp="2025-02-27 12:21:33",
NodeId="192.0.2.2",
CompId="cc-smca-mgmt",
InfoMsg="Updated Global System Property lock_out_setting to true",
SenderType="Management Server",
EventId="2575083827416288586",
UserOriginator="radmin",
ClientIpAddress="192.168.200.1",
TypeDescription="stonegate.object.update",
Result="Success",
ObjectName="lock_out_setting"
Timestamp="2025-02-27 12:21:33",
NodeId="192.0.2.2",
CompId="cc-smca-mgmt",
InfoMsg="Updated Global System Property max_failed_logins_per_source_before_delay to 3",
SenderType="Management Server",
EventId="2575083827416288587",
UserOriginator="radmin",
ClientIpAddress="192.168.200.1",
TypeDescription="stonegate.object.update",
Result="Success",
ObjectName="max_failed_logins_per_source_before_delay"
Timestamp="2025-02-27 12:21:33",
NodeId="192.0.2.2",
CompId="cc-smca-mgmt",
InfoMsg="Updated Global System Property failed_auth_attempt_before_delay to 5",
SenderType="Management Server",
EventId="2575083827416288589",
UserOriginator="radmin",
ClientIpAddress="192.168.200.1",
TypeDescription="stonegate.object.update",
Result="Success",
ObjectName="failed_auth_attempt_before_delay"
Timestamp="2025-02-27 12:21:33",
NodeId="192.0.2.2",CompId="cc-smca-mgmt",
InfoMsg="Updated Global System Property conf_time_all_login_per_source_delayed to 15",
SenderType="Management Server",
EventId="2575083827416288588",UserOriginator="radmin",
ClientIpAddress="192.168.200.1",
TypeDescription="stonegate.object.update",
Result="Success",
ObjectName="conf_time_all_login_per_source_delayed"
Timestamp="2025-02-27 12:21:33",
NodeId="192.0.2.2",
CompId="cc-smca-mgmt",
InfoMsg="Created Global System Property conf_period_for_failed_login_before_lock with values 60",
SenderType="Management Server",
EventId="2575083827416288591",
UserOriginator="radmin",
ClientIpAddress="192.168.200.1",
TypeDescription="stonegate.object.insert",
Result="Success",
ObjectName="conf_period_for_failed_login_before_lock"
Timestamp="2025-03-05 23:05:02",
NodeId="192.0.2.2",
CompId="cc-smca-mgmt",
SenderType="Management Server",
EventId="7530035494839648441",
UserOriginator="radmin",
ClientIpAddress="192.168.200.1",
TypeDescription="stonegate.admin.disabled",
Result="Success",
ObjectName="smcadmin"

Configure authentication failure parameters for FIA_AFL.1

(Continued)

Timestamp="2025-02-27 12:21:33",
NodeId="192.0.2.2",
CompId="cc-smca-mgmt",
InfoMsg="Updated Global System Property conf_time_all_login_per_source_delayed to 15",
SenderType="Management Server",
EventId="2575083827416288588",
UserOriginator="radmin",
ClientIpAddress="192.168.200.1",
TypeDescription="stonegate.object.update",
Result="Success",
ObjectName="conf_time_all_login_per_source_delayed"
Timestamp="2025-02-27 12:21:33",
NodeId="192.0.2.2",
CompId="cc-smca-mgmt",
InfoMsg="Created Global System Property conf_period_for_failed_login_before_lock with values 60",
SenderType="Management Server",
EventId="2575083827416288591",
UserOriginator="radmin",
ClientIpAddress="192.168.200.1",
TypeDescription="stonegate.object.insert",
Result="Success",
ObjectName="conf_period_for_failed_login_before_lock"
Timestamp="2025-03-05 23:05:02",
NodeId="192.0.2.2",
CompId="cc-smca-mgmt",
SenderType="Management Server",
EventId="7530035494839648441",
UserOriginator="radmin",
ClientIpAddress="192.168.200.1",
TypeDescription="stonegate.admin.disabled",
Result="Success",
ObjectName="smcadmin"

Auditable event Configuration of time
Configuration of a new time server

Timestamp="2025-03-06 14:20:13",
NodeId="192.0.2.2",
CompId="cc-smca-mgmt",
InfoMsg="ntp_server element has been created.",
SenderType="Management Server",
EventId="7765054971405402282",
UserOriginator="radmin",
ClientIpAddress="192.168.200.1",
TypeDescription="stonegate.object.insert",
Result="Success",
ObjectName="cc-audit-ntp"

Auditable event Configuration of the cryptographic functionality
Configure the cryptographic functionality for TLS

Timestamp="2025-03-06 14:43:58",
NodeId="192.0.2.2",
CompId="cc-smca-mgmt",
InfoMsg="tls_cryptography_suite_set element has been created.",
SenderType="Management Server",
EventId="7765054971405402348",
UserOriginator="priadmin",
ClientIpAddress="192.168.200.1",
TypeDescription="stonegate.object.insert",
Result="Success",
ObjectName="CC TLS Suite"
Timestamp="2025-03-07 12:02:33",
NodeId="192.0.2.2",
CompId="cc-smca-mgmt",
InfoMsg="tls_cryptography_suites has been modified on its attribute: tls_ecdhe_rsa_with_aes_128_cbc_sha (true -> false).",
SenderType="Management Server",
EventId="7765054971405403576",
UserOriginator="radmin",
ClientIpAddress="192.168.200.1",
TypeDescription="stonegate.object.update.details",
Result="Success",
ObjectName="CC TLS Suite"
Timestamp="2025-03-07 12:02:33",
NodeId="192.0.2.2",
CompId="cc-smca-mgmt",
SenderType="Management Server",
EventId="7765054971405403577",
UserOriginator="radmin",
ClientIpAddress="192.168.200.1",
TypeDescription="stonegate.object.update",
Result="Success",
ObjectName="CC TLS Suite"
Timestamp="2025-03-07 12:11:54",
NodeId="192.0.2.2",
CompId="cc-smca-mgmt",
InfoMsg="web_app (webswing) has been modified on its attribute: tls_cipher_suites (Forcepoint Approved (v1) TLS Cryptographic Algorithms -> CC TLS Suite).",
SenderType="Management Server",
EventId="7765054971405403606",
UserOriginator="radmin",
ClientIpAddress="192.168.200.1",
TypeDescription="stonegate.object.update.details",
Result="Success",
ObjectName="cc-smca-mgmt"

Configure the cryptographic functionality for TLS

(continued)

Timestamp="2025-03-07 15:06:19",
NodeId="192.0.2.2",
CompId="cc-smca-mgmt",
InfoMsg="tls_cryptography_suite_set_ref has been modified (NIST (SP 800-52 Rev. 2) Compatible TLS Cryptographic Algorithms -> CC TLS Suite).",
SenderType="Management Server",
EventId="7765054971405404028",
UserOriginator="radmin",
ClientIpAddress="192.168.200.1",
TypeDescription="stonegate.object.update.details",
Result="Success",
ObjectName="Audit Syslog TLS Profile"
Timestamp="2025-03-07 15:06:19",
NodeId="192.0.2.2",
CompId="cc-smca-mgmt",
SenderType="Management Server",
EventId="7765054971405404029",
UserOriginator="radmin",
ClientIpAddress="192.168.200.1",
TypeDescription="stonegate.object.update",
Result="Success",
ObjectName="Audit Syslog TLS Profile"
Timestamp="2025-03-14 11:43:38",
NodeId="192.0.2.2",
CompId="cc-smca-mgmt",
InfoMsg="netflow_collector has been modified on its attribute: tls_profile (No value -> Audit Syslog TLS Profile).",
SenderType="Management Server",
EventId="803323531923297561",
UserOriginator="radmin",
ClientIpAddress="192.168.200.1",
TypeDescription="stonegate.object.update.details",
Result="Success",
ObjectName="cc-smca-mgmt"
Timestamp="2025-03-14 11:43:38",
NodeId="192.0.2.2",
CompId="cc-smca-mgmt",
InfoMsg="netflow_collector has been modified on its attribute: netflow_collector_service (tcp -> tcp_with_tls).",
SenderType="Management Server",
EventId="803323531923297562",
UserOriginator="radmin",
ClientIpAddress="192.168.200.1",
TypeDescription="stonegate.object.update.details",
Result="Success",
ObjectName="cc-smca-mgmt"
Timestamp="2025-03-14 11:43:38",
NodeId="192.0.2.2",
CompId="cc-smca-mgmt",
InfoMsg="netflow_collector has been modified on its attribute: tls_identity (No value -> IP Address / 192.0.2.101).",
SenderType="Management Server",
EventId="803323531923297563",
UserOriginator="radmin",
ClientIpAddress="192.168.200.1",
TypeDescription="stonegate.object.update.details",
Result="Success",
ObjectName="cc-smca-mgmt"

Configure the cryptographic functionality for NTP

Timestamp="2025-03-06 14:46:58",
NodeId="192.0.2.2",
CompId="cc-smca-mgmt",
InfoMsg="ntp_auth_key_type has been modified (none -> SHA1).",
SenderType="Management Server",
EventId="7765054971405402359",
UserOriginator="radmin",
ClientIpAddress="192.168.200.1",
TypeDescription="stonegate.object.update.details",
Result="Success",
ObjectName="cc-audit-ntp"
Timestamp="2025-03-06 14:46:58",
NodeId="192.0.2.2",
CompId="cc-smca-mgmt",
SenderType="Management Server",
EventId="7765054971405402360",
UserOriginator="radmin",
ClientIpAddress="192.168.200.1",
TypeDescription="stonegate.object.update",
Result="Success",
ObjectName="cc-audit-ntp"

Auditable event Generating / import of, changing, or deleting of cryptographic keys
Creation of a TLS private key (Administration > Certificates > TLS Credentials > New TLS Credentials)

Timestamp="2025-03-17 17:23:15",
NodeId="192.0.2.2",
CompId="Management Server",
InfoMsg="Private Key (Algorithm: ECDSA. Size: 384)",
SenderType="Management Server",
EventId="2674752396105613423",
UserOriginator="test00",
ClientIpAddress="192.0.2.1",
TypeDescription="stonegate.cryptographic_key.new",
Result="Success",
ObjectName="Management Server"

Certificate signing request

Timestamp="2025-03-17 16:52:37",
NodeId="192.0.2.2",
CompId="Management Server",
InfoMsg="Management Server certificate signing request was exported. The fingerprint is 5D:A2:1E:B5:EE:E9:17:9C:2F:3C:5E:AA:F5:48:CA:A3:26:16:30:88.",
SenderType="Management Server",
EventId="2666836548040786061",
UserOriginator="test00",
ClientIpAddress="192.0.2.1",
TypeDescription="stonegate.certificaterequest.export",
Result="Success",
ObjectName="Management Server"

Import signed certificate

Timestamp="2025-03-17 16:51:11",
NodeId="192.0.2.2",
CompId="Management Server",
InfoMsg="CN=LogServer 192.0.2.2: Algorithm EC. Key size 384. Validity Tue Apr 15 16:51:10 GMT 2025",
SenderType="Management Server",
EventId="2666836548040785992",
UserOriginator="test00",
ClientIpAddress="192.0.2.1",
TypeDescription="stonegate.certificate.import",
Result="Success",
ObjectName="LogServer 192.0.2.2"

Deletion (from Trash)

Timestamp="2025-02-14 13:41:09",
NodeId="192.0.2.2",
CompId="Management Server",
EventId="338060036964089860",
OriginName="MgtServer Tool",
UserOriginator="System",
ClientIpAddress="192.0.2.2",
TypeDescription="stonegate.cryptographic_key.deleted",
Result="Success",
ObjectName="Management Server"

Import of a trusted certificate authority (CA)

Timestamp="2025-03-17 16:45:08",
NodeId="192.0.2.2",
CompId="Management Server",
SenderType="Management Server",
EventId="2663570813822697742",
UserOriginator="test00",
ClientIpAddress="192.0.2.1",
TypeDescription="stonegate.ca.internal.trust.start",
Result="Success",
ObjectName="  [0]         Version: 3         SerialNumber: 290537198474842792658101195459566188220737020075             
IssuerDN: CN=ext_pki-styx-ca certificate  L=Helsinki  C=FI           Start Date: Mon Mar 17 16:45:07 GMT 2025           
Final Date: Thu Sep 28 16:45:07 GMT 2045            
SubjectDN: CN=ext_pki-styx-ca certificate  L=Helsinki  C=FI           
Public Key: EC Public Key [7a:ce:6c:f3:43:68:df:09:2b:e1:b7:82:5e:e8:f9:28:75:a8:f8:dc]           
X: 1c25b5a47d5cde5ecfa5283dc248985956c748a6b4703f109689ada67
   d951fb5778d0cdf2bbbce590306d21de761489b            
Y: c6ec13c2cbd9675934b675f2c8a0f5cedf7458af4d23a20c77048ccdd
   c0670035518ef4f4a25b461197083c5046f6834  
Signature Algorithm: SHA384WITHECDSA            Signature: 3064023024052c2cc1bbfddb1ab9022d0db6d115                      
 5cbc03339c7f7d6c4086ec461e641abe8ce4e3ad                       9c150b2304fb4cc37bfda30d0230645287efa16d 
                      4a8fdbd5ee3e19331c6b6a32493c66697b586363                       24ca541263cd611c57cb75257ff3f257f8b7a7b8                      
 d99d       Extensions:                        critical(false) 2.5.29.14 value = DER Octet String[20]                        
critical(true) BasicConstraints: isCa(true)                       critical(true) KeyUsage: 0x86"
Timestamp="2025-03-17 16:45:08",
NodeId="192.0.2.2",
CompId="Management Server",
SenderType="Management Server",
EventId="2663570813822697743",
UserOriginator="test00",
ClientIpAddress="192.0.2.1",
TypeDescription="stonegate.ca.internal.trust.start",
Result="Success",
ObjectName="CN=ext_pki-styx-ca certificate L=Helsinki C=FI"

Import of a private key and a certificate

Timestamp="2025-03-18 10:50:36",
NodeId="192.0.2.2",
CompId="Management Server",
InfoMsg="Cryptographic key imported",
SenderType="Management Server",
EventId="2939203183311848077",
UserOriginator="test00",
ClientIpAddress="192.0.2.1",
TypeDescription="stonegate.cryptographic_key.import",
Result="Success",
ObjectName="example_creds"
Timestamp="2025-03-18 10:50:36",
NodeId="192.0.2.2",
CompId="Management Server",
SenderType="Management Server",
EventId="2939203183311848078",
UserOriginator="test00",
ClientIpAddress="192.0.2.1",
TypeDescription="stonegate.certificate.import",
Result="Success",
ObjectName="example_creds"
Timestamp="2025-03-18 10:50:36",
NodeId="192.0.2.2",
CompId="Management Server",
SenderType="Management Server",
EventId="2939203183311848079",
UserOriginator="test00",
ClientIpAddress="192.0.2.1",
TypeDescription="stonegate.object.insert",
Result="Success",
ObjectName="example_creds"

Removal (Deletion) of a Trusted Certificate Authority

Timestamp="2025-03-18 11:06:54",
NodeId="192.0.2.2",
CompId="Management Server",
SenderType="Management Server",
EventId="2939203183311848443",
UserOriginator="test00",
ClientIpAddress="192.0.2.1",
TypeDescription="stonegate.object.delete",
Result="Success",
ObjectName="example_trustedCA"
Timestamp="2025-03-18 11:06:54",
NodeId="192.0.2.2",
CompId="Management Server",
SenderType="Management Server",
EventId="2939203183311848444",
UserOriginator="test00",
ClientIpAddress="192.0.2.1",
TypeDescription="stonegate.cryptographic_key.deleted",
Result="Success",
ObjectName="example_trustedCA"
Timestamp="2025-03-18 11:06:54",
NodeId="192.0.2.2",
CompId="Management Server",
InfoMsg="Certificate of a Certificate Authority with subject name CN=intermCA OU=Silicon O=Forcepoint L=Helsinki ST=Uusimaa C=FI.",
SenderType="Management Server",
EventId="2939203183311848445",
UserOriginator="test00",
ClientIpAddress="192.0.2.1",
TypeDescription="stonegate.certificate.delete",
Result="Success"

Auditable event Resetting passwords
Password reset

Timestamp="2025-03-14 13:16:38",
NodeId="192.0.2.2",
CompId="cc-smca-mgmt",
SenderType="Management Server",
EventId="803323531923297856",
UserOriginator="radmin",
ClientIpAddress="192.168.200.1",
TypeDescription="stonegate.admin.enginepassword.change",
Result="Success",
ObjectName="smcadmin"
Timestamp="2025-03-14 13:16:38",
NodeId="192.0.2.2",
CompId="cc-smca-mgmt",
SenderType="Management Server",
EventId="803323531923297855",
UserOriginator="radmin",
ClientIpAddress="192.168.200.1",
TypeDescription="stonegate.admin.password.change",
Result="Success",
ObjectName="smcadmin"

Table 2.
FCS_NTP_EXT.1, FAU_GEN.1.1 c)
Configuration of a new time server

Timestamp="2025-03-14 13:35:25",
NodeId="192.0.2.2",CompId="cc-smca-mgmt",
InfoMsg="ntp_server_ref has been added: <ntp_server_ref ref='cc-ntp-2'/>.",
SenderType="Management Server",
EventId="803323531923297906",
UserOriginator="radmin",
ClientIpAddress="192.168.200.1",
TypeDescription="stonegate.object.update.details",
Result="Success",
ObjectName="cc-ngfw"
Timestamp="2025-03-14 13:35:25",
NodeId="192.0.2.2",
CompId="cc-smca-mgmt",
InfoMsg="ntp_settings has been modified on its attribute: ntp_preferred_server_ref (No value -> cc-ntp-2).",
SenderType="Management Server",
EventId="803323531923297905",
UserOriginator="radmin",
ClientIpAddress="192.168.200.1",
TypeDescription="stonegate.object.update.details",
Result="Success",
ObjectName="cc-ngfw

Removal of configured time server

Timestamp="2025-03-14 13:38:13",
NodeId="192.0.2.2",
CompId="cc-smca-mgmt",
InfoMsg="ntp_server_ref has been removed: <ntp_server_ref ref='cc-ntp-2'/>.",
SenderType="Management Server",
EventId="803323531923297915",
UserOriginator="radmin",
ClientIpAddress="192.168.200.1",
TypeDescription="stonegate.object.update.details",
Result="Success",
ObjectName="cc-ngfw"
Timestamp="2025-03-14 13:38:13",
NodeId="192.0.2.2",
CompId="cc-smca-mgmt",
InfoMsg="ntp_settings has been modified on its attribute: ntp_preferred_server_ref (cc-ntp-2 -> No value).",
SenderType="Management Server",
EventId="803323531923297914",
UserOriginator="radmin",
ClientIpAddress="192.168.200.1",
TypeDescription="stonegate.object.update.details",
Result="Success",
ObjectName="cc-ngfw"
Timestamp="2025-03-14 13:40:01",
NodeId="192.0.2.2",
CompId="cc-smca-mgmt",
SenderType="Management Server",
EventId="803323531923297919",
UserOriginator="radmin",
ClientIpAddress="192.168.200.1",
TypeDescription="stonegate.trash.add",
Result="Success",
ObjectName="cc-ntp-2"
Timestamp="2025-03-14 13:40:14",
NodeId="192.0.2.2",
CompId="cc-smca-mgmt",
SenderType="Management Server",
EventId="803323531923297921",
UserOriginator="radmin",
ClientIpAddress="192.168.200.1",
TypeDescription="stonegate.object.delete",
Result="Success",
ObjectName="cc-ntp-2"

Manual time change

Timestamp="2025-03-17 11:50:55",
NodeId="127.0.0.1",
Type="Notification",
CompId="3",
InfoMsg="Mar 17 11:50:55 cc-audit-smca sudo: radmin : TTY=tty1 ; PWD=/home/radmin ; USER=root ; COMMAND=/bin/date -s 'Mar 17 11:55:55 UTC 2025'",
ReceptionTime="2025-03-17 11:50:55",
SenderType="Third Party Device",
EventId="72"

Table 3.
FMT SMF.1/FFW FAU_GEN.1.1 c)
Engine filtering rule change

Timestamp="2025-03-17 17:10:07",
NodeId="192.0.2.2",
CompId="Management Server",
InfoMsg="rule_entry (@134.1) has been modified on its attribute: is_disabled (false -> true).",
SenderType="Management Server",
EventId="2670690370655879358",
UserOriginator="test00",
ClientIpAddress="192.0.2.1",
TypeDescription="stonegate.object.update.details",
Result="Success",
ObjectName="Allow FTP and SSH"

Engine security policy change

Timestamp="2025-03-17 17:10:08",
NodeId="192.0.2.2",
CompId="Management Server",
InfoMsg="Upload started from REST API",
SenderType="Management Server",
EventId="2670690370655879363",
UserOriginator="test00",
ClientIpAddress="192.0.2.1",
TypeDescription="stonegate.policy.upload.start",
Result="Success",
ObjectName="Allow FTP and SSH policy;ngfw"
Timestamp="2025-03-17 17:10:25",
NodeId="192.0.2.2",
CompId="Management Server",
InfoMsg="Upload started from REST API",
SenderType="Management Server",
EventId="2670690370655879370",
UserOriginator="test00",
ClientIpAddress="192.0.2.1",
TypeDescription="stonegate.policy.upload.end",
Result="Success",
ObjectName="Allow FTP and SSH policy;ngfw"

Engine security policy change

(add rule)

Timestamp="2025-03-17 17:10:07",
NodeId="192.0.2.2",
CompId="Management Server",
InfoMsg="access_entry has been added: <rule_entry is_disabled='false' parent_rule_ref='Access rule : insert point' rank='1.0' tag='132.0'><match_part><match_sources><match_source_ref type='network_element' value='ANY'/></match_sources><match_destinations><match_destination_ref type='network_element' value='ANY'/></match_destinations><match_services><match_service_ref type='application' value='FTP'/></match_services></match_part><option><log_policy closing_mode='true' log_level='undefined' mss_enforce='false'><payload_modes><payload_mode type='string' value='nothing'/></payload_modes></log_policy></option></rule_entry>.",
SenderType="Management Server",
EventId="2670690370655879346",
UserOriginator="test00",
ClientIpAddress="192.0.2.1",
TypeDescription="stonegate.object.update.details",
Result="Success",
ObjectName="Allow FTP and SSH"
 Timestamp="2025-03-17 17:10:07",
NodeId="192.0.2.2",
CompId="Management Server",
SenderType="Management Server",
EventId="2670690370655879350",
UserOriginator="test00",
ClientIpAddress="192.0.2.1",
TypeDescription="stonegate.object.update",
Result="Success",
ObjectName="Allow FTP and SSH"

Engine security policy change

(delete rule)

Timestamp="2025-03-18 13:45:04",
NodeId="192.0.2.2",
RuleId="134.1",
CompId="Management Server",
InfoMsg="IPv4 Access @134.1 has been deleted.",
SenderType="Management Server",
EventId="2987302565009424679",
UserOriginator="test00",
ClientIpAddress="192.0.2.1",
TypeDescription="stonegate.object.delete",
Result="Success",
ObjectName="Allow FTP and SSH policy"
Timestamp="2025-03-18 13:45:04",
NodeId="192.0.2.2",
CompId="Management Server",
InfoMsg="rule_entry (@134.1) has been removed: <rule_entry name='discard all' is_disabled='true' parent_rule_ref='Access rule : insert point' rank='-50.0' rule_tag_major_id='134' tag='134.1'><match_part><match_sources><match_source_ref type='network_element' value='ANY'/></match_sources><match_destinations><match_destination_ref type='network_element' value='ANY'/></match_destinations><match_services><match_service_ref type='service' value='ANY'/></match_services></match_part><option><log_policy closing_mode='true' log_level='undefined' mss_enforce='false'><payload_modes><payload_mode type='string' value='nothing'/></payload_modes></log_policy></option></rule_entry>.",
SenderType="Management Server",
EventId="2987302565009424680",
UserOriginator="test00",
ClientIpAddress="192.0.2.1",
TypeDescription="stonegate.object.update.details",
Result="Success",
ObjectName="Allow FTP and SSH policy"

Engine security policy change

(create policy)

Timestamp="2025-03-17 17:10:06",
NodeId="192.0.2.2",
CompId="Management Server",
InfoMsg="fw_policy element has been created.",
SenderType="Management Server",
EventId="2670690370655879343",
UserOriginator="test00",
ClientIpAddress="192.0.2.1",
TypeDescription="stonegate.object.insert",
Result="Success",
ObjectName="Allow FTP and SSH"

Engine security policy change

(upload policy)

Timestamp="2025-03-17 17:10:08",
NodeId="192.0.2.2",
CompId="Management Server",
InfoMsg="Upload started from REST API",
SenderType="Management Server",
EventId="2670690370655879363",
UserOriginator="test00",
ClientIpAddress="192.0.2.1",
TypeDescription="stonegate.policy.upload.start",
Result="Success",
ObjectName="Allow FTP and SSH policy;ngfw"
Timestamp="2025-03-17 17:10:25",
NodeId="192.0.2.2",
CompId="Management Server",
SenderType="Management Server",
EventId="2670690370655879369",
UserOriginator="test00",
ClientIpAddress="192.0.2.1",
TypeDescription="stonegate.firewall.policy.upload",
Result="Success",
ObjectName="ngfw;Allow FTP and SSH policy"
Timestamp="2025-03-17 17:10:25",
NodeId="192.0.2.2",
CompId="Management Server",
InfoMsg="Upload started from REST API",
SenderType="Management Server",
EventId="2670690370655879370",
UserOriginator="test00",
ClientIpAddress="192.0.2.1",
TypeDescription="stonegate.policy.upload.end",
Result="Success",
ObjectName="Allow FTP and SSH policy;ngfw"

Firewall security policy change

(delete policy)

Timestamp="2025-03-17 17:10:34",
NodeId="192.0.2.2",
CompId="Management Server",
SenderType="Management Server",
EventId="2670690370655879373",
UserOriginator="test00",
ClientIpAddress="192.0.2.1",
TypeDescription="stonegate.object.delete",
Result="Success",
ObjectName="Allow FTP and SSH policy"

Table 4.
FMT_SMF.1/VPN, FAU_GEN.1.1 c) VPN security policy change
VPN security policy change (adding rule)

Timestamp="2025-03-26 14:47:31",
NodeId="192.0.2.2",
CompId="Management Server",
InfoMsg="rule_entry (@123.0) has been added: <rule_entry name='discard ISAKMP and NAT-T' is_disabled='false' parent_rule_ref='Access rule : insert point' rank='-25.0' rule_tag_major_id='123' tag='123.0'><match_part><match_sources><match_source_ref type='network_element' value='ANY'/></match_sources><match_destinations><match_destination_ref type='network_element' value='$$ Local Cluster'/></match_destinations><match_services><match_service_ref type='application' value='ISAKMP'/><match_service_ref type='application' value='NAT-T'/></match_services><rule_validity_times><rule_validity_time_ref type='rule_validity_time' value='Weekends'/></rule_validity_times></match_part><option><log_policy closing_mode='true' log_level='undefined' mss_enforce='false'><payload_modes><payload_mode type='string' value='nothing'/></payload_modes></log_policy></option></rule_entry>.",
SenderType="Management Server",
EventId="5973932190247944426",
UserOriginator="test00",
ClientIpAddress="192.0.2.1",
TypeDescription="stonegate.object.update.details",
Result="Success",
ObjectName="auditpolicy"
Timestamp="2025-03-26 14:47:31",
NodeId="192.0.2.2",
RuleId="123.0",
CompId="Management Server",
InfoMsg="IPv4 Access @123.0 has been added.",
SenderType="Management Server",
EventId="5973932190247944425",
UserOriginator="test00",
ClientIpAddress="192.0.2.1",
TypeDescription="stonegate.object.insert",
Result="Success",
ObjectName="auditpolicy"
VPN security policy change (modify rule)

Timestamp="2025-03-26 14:47:33",
NodeId="192.0.2.2",
CompId="Management Server",
InfoMsg="match_source_ref has been added: <match_source_ref type='network_element' value='network-192.0.2.0/24'/>.",
SenderType="Management Server",
EventId="5973932190247944430",
UserOriginator="test00",
ClientIpAddress="192.0.2.1",
TypeDescription="stonegate.object.update.details",
Result="Success",
ObjectName="auditpolicy"
Timestamp="2025-03-26 14:47:33",
NodeId="192.0.2.2",
RuleId="123.1",
CompId="Management Server",
InfoMsg="IPv4 Access @123.1 has been modified.",
SenderType="Management Server",
EventId="5973932190247944428",
UserOriginator="test00",
ClientIpAddress="192.0.2.1",
TypeDescription="stonegate.object.update",
Result="Success",
ObjectName="auditpolicy"
VPN security policy change (delete rule)

Timestamp="2025-03-26 14:47:35",
NodeId="192.0.2.2",RuleId="123.1",
CompId="Management Server",
InfoMsg="IPv4 Access @123.1 has been deleted.",
SenderType="Management Server",
EventId="5973932190247944432",
UserOriginator="test00",
ClientIpAddress="192.0.2.1",
TypeDescription="stonegate.object.delete",
Result="Success",
ObjectName="auditpolicy"
Timestamp="2025-03-26 14:47:38",
NodeId="192.0.2.2",
CompId="Management Server",
InfoMsg="rule_entry (@123.1) has been removed: <rule_entry name='discard ISAKMP and NAT-T' is_disabled='false' parent_rule_ref='Access rule : insert point' rank='-25.0' rule_tag_major_id='123' tag='123.1'><match_part><match_sources><match_source_ref type='network_element' value='network-192.0.2.0/24'/></match_sources><match_destinations><match_destination_ref type='network_element' value='$$ Local Cluster'/></match_destinations><match_services><match_service_ref type='application' value='ISAKMP'/><match_service_ref type='application' value='NAT-T'/></match_services><rule_validity_times><rule_validity_time_ref type='rule_validity_time' value='Weekends'/></rule_validity_times></match_part><option><log_policy closing_mode='true' log_level='undefined' mss_enforce='false'><payload_modes><payload_mode type='string' value='nothing'/></payload_modes></log_policy></option></rule_entry>.",
SenderType="Management Server",
EventId="5973932190247944434",
UserOriginator="test00",
ClientIpAddress="192.0.2.1",
TypeDescription="stonegate.object.update.details",
Result="Success",
ObjectName="auditpolicy"
Table 5.
FPT_STM_EXT.1
NTP time change

Timestamp="2025-04-07 13:55:52",
NodeId="127.0.0.1",
Type="Notification",
CompId="3",
InfoMsg="Apr 7 13:55:52 cc-smca chronyd[290768]: Backward time jump detected!",
ReceptionTime="2025-04-07 13:55:52",
SenderType="Third Party Device",
EventId="11456"
Timestamp="2025-04-07 15:14:14",
NodeId="127.0.0.1",
Type="Notification",
CompId="3",
InfoMsg="Apr 7 15:14:14 cc-smca chronyd[290768]: System clock was stepped by 4571.600739 seconds",
ReceptionTime="2025-04-07 15:14:14",
SenderType="Third Party Device",
EventId="11460"
Timestamp="2025-04-07 16:15:53",
NodeId="127.0.0.1",
Type="Notification",
CompId="3",
InfoMsg="Apr 7 16:15:53 cc-smca chronyd[290768]: Forward time jump detected!",
ReceptionTime="2025-04-07 16:15:53",
SenderType="Third Party Device",
EventId="11540"

NTP time change

(Continued)

Timestamp="2025-04-07 15:17:29",
NodeId="127.0.0.1",
Type="Notification",
CompId="3",
InfoMsg="Apr 7 15:17:29 cc-smca chronyd[290768]: System clock was stepped by -3634.485642 seconds",
ReceptionTime="2025-04-07 15:17:29",
SenderType="Third Party Device",
EventId="11544"
Timestamp="2025-04-08 12:48:41",
LogId="818214",
NodeId="192.0.2.4",
Facility="Syslog",
Type="Notification",
CompId="cc-ngfw-1 node 1",
InfoMsg="ntpd: Time change. Before: Tue Apr  8 12:44:08   After: Tue Apr  8 12:48:41   Peer: 192.0.2.123",
ReceptionTime="2025-04-08 12:48:47",
SenderType="Firewall",
EventId="7315354900329430054"

Table 6.
FCS_TLSC_EXT.1
Auditable event TLS client sessions
Failure to establish a TLS client session

Timestamp="2025-03-14 11:55:05",
NodeId="192.0.2.2",
CompId="Management Server",
InfoMsg="TLS Connection failed : Protocol = NONE  Peer = [host=192.0.2.10  port=2055]  Local = [host=192.0.2.2  port=35696] ERROR: Syslog authentication failed. [/192.0.2.10:2055] Details: certificate expired on 20200102080000GMT+00:00",
SenderType="Management Server",
EventId="1476204865502838960",
UserOriginator="System",
ClientIpAddress="192.0.2.10",
TypeDescription="stonegate.trusted.connection.failure",
Result="Fail"

Table 7.
FCS_TLSS_EXT.1,FCS_HTTPS_EXT.1,FTP_TRP.1/Admin
Auditable event HTTPS and TLS sessions, and trusted path
Initiation of an HTTPS or TLS session, or trusted path

Timestamp="2025-03-18 13:44:04",
NodeId="192.0.2.2",
CompId="Management Server",
InfoMsg="TLS Connection started : Protocol = TLSv1.2  Peer = [host=192.0.2.1  port=57556]  Local = [host=192.0.2.2  port=8085]",
SenderType="Management Server",
EventId="2987302565009424613",
UserOriginator="System",
ClientIpAddress="192.0.2.1",
TypeDescription="stonegate.trusted.connection.start",
Result="Success"

Termination of an HTTPS or TLS session, or trusted path

Timestamp="2025-03-18 13:45:06",
NodeId="192.0.2.2",
CompId="Management Server",
InfoMsg="TLS Connection ended : Protocol = TLSv1.2  Peer = [host=192.0.2.1  port=57556]  Local = [host=192.0.2.2  port=8085]",
SenderType="Management Server",
EventId="2987302565009424682",
UserOriginator="System",
ClientIpAddress="192.0.2.1",
TypeDescription="stonegate.trusted.connection.end",
Result="Success"

Failure to establish an HTTPS or TLS session, or trusted path

Timestamp="2025-03-17 17:38:24",
NodeId="192.0.2.2",
CompId="Management Server",
InfoMsg="TLS Connection failed : Protocol = NONE  Peer = [host=192.0.2.2  port=36208]  Local = [host=192.0.2.2  port=3023] ERROR: Communication authentication failed. [192.0.2.2:36208] Details: Failed to check certificate Certificate Error:  KeyUsage extension not present in CA certificate",
SenderType="Management Server",
EventId="2675169377300513405",
UserOriginator="System",
ClientIpAddress="192.0.2.2",
TypeDescription="stonegate.trusted.connection.failure",
Result="Fail"

FCS_TLSS_EXT.2
Auditable event TLS sessions
Failure to authenticate the client

(SMC as a server)

Timestamp="2025-03-17 16:51:33",
NodeId="192.0.2.2",
CompId="Management Server",
InfoMsg="TLS Connection failed : Protocol = NONE  Peer = [host=192.0.2.2  port=39142]  Local = [host=192.0.2.2  port=3023] ERROR: Communication authentication failed. [192.0.2.2:39142] Details: Failed to check certificate Certificate Error:  The Certificate (subjectDN=CN=ext_pki-ocsp-ic certificate C=FI  serialNumber=1):  Certificate has been revoked  reason: KEY_COMPROMISE  revocation date: Mon Mar 17 16:50:27 GMT 2025  authority: CN=ext_pki-ocsp-ca certificate  L=Helsinki  C=FI  extension OIDs: []",
SenderType="Management Server",
EventId="2665307750136807714",
UserOriginator="System",
ClientIpAddress="192.0.2.2",
TypeDescription="stonegate.trusted.connection.failure",
Result="Fail"

Failure to authenticate the client

(Security Engine as a server)

Timestamp="2025-03-17 17:22:53",
LogId="1975",
NodeId="192.0.2.4",
Facility="Management",
Type="Error",
CompId="ngfw node 1",
InfoMsg="peer did not return a certificate",
ReceptionTime="2025-03-17 17:22:54",
SenderType="Firewall",
SituationId="9005",
Situation="FW_Communication-Communication-Error",
EventId="7307451370229991351"
Timestamp="2025-03-17 17:22:53",
LogId="1976",
NodeId="192.0.2.4",
Facility="Management",
Type="Notification",
CompId="ngfw node 1",
InfoMsg="TLS: Couldn't accept TLS connection: -3 (DNS:ManagementServer  192.0.2.2)",
ReceptionTime="2025-03-17 17:22:54",
SenderType="Firewall",
SituationId="78002",
Situation="TLS connection state",
EventId="7307451370229991352"

FFW_RUL_EXT.1

Half-open connection limit

Timestamp="2025-03-27 12:22:46",
LogId="2693",
NodeId="192.0.2.4",
Facility="Packet Filtering",
Type="Notification",
Dst="203.0.113.6",
CompId="ngfw node 1",
InfoMsg="Protection started Trigger: half-open limit",
ReceptionTime="2025-03-27 12:22:47",
SenderType="Firewall",
SituationId="79990",
Situation="DOS_SYN-Flood-Started",
EventId="7310999726181057677"
Auditable event Application of rules configured with the 'log' operation
Connection allowed

Timestamp="2025-03-18 13:37:46",
LogId="884",
NodeId="192.0.2.4",
Facility="Inspection",
Type="Notification",
Event="New connection",
Action="Allow",
Protocol="6",
Src="198.51.100.6",
Dst="203.0.113.6",
Sport="44484",
Dport="21",
RuleId="132.0",
Srcif="1",
CompId="ngfw node 1",
ReceptionTime="2025-03-18 13:37:47",
SenderType="Firewall",
SituationId="70018",
Situation="Connection_Allowed",
EventId="7307757111144186405",
Service="FTP"

Connection discarded

Timestamp="2025-03-17 17:10:19",
LogId="871",
NodeId="192.0.2.4",
Facility="Packet Filtering",
Type="Notification",
Event="Connection discarded",
Action="Discard",
Protocol="58",
Src="::16",
Dst="FF02::16",
RuleId="46.0",
Srcif="0",
IcmpType="143",
IcmpCode="0",
CompId="ngfw node 1",
ReceptionTime="2025-03-17 17:10:20",
SenderType="Firewall",
SituationId="70019",
Situation="Connection_Discarded",
EventId="7307448209134059546",
Service="IPv6 ICMP/143/0"

FFW_RUL_EXT.2
Auditable event Dynamical definition of rule and establishment of a session
Dynamical definition of rule and establishment of a session

Timestamp="2025-03-17 17:10:33",
LogId="932",
NodeId="192.0.2.4",
Facility="Inspection",
Type="Notification",
Event="New connection",
Action="Allow",
Protocol="6",
Src="198.51.100.6",
Dst="203.0.113.6",
Sport="51142",
Dport="21",
RuleId="132.0",
Srcif="1",
CompId="ngfw node 1",
ReceptionTime="2025-03-17 17:10:34",
SenderType="Firewall",
SituationId="70018",
Situation="Connection_Allowed",
EventId="7307448268685485565",
Service="FTP"

 Timestamp="2025-03-17 17:10:33",
LogId="934",
NodeId="192.0.2.4",
Facility="Packet Filtering",
Type="Notification",
Event="Related connection",
Action="Allow",
Protocol="6",
Src="198.51.100.6",
Dst="203.0.113.6",
Sport="46660",
Dport="51332",
RuleId="132.0",
Srcif="1;1",
CompId="ngfw node 1",
ReceptionTime="2025-03-17 17:10:34",
SenderType="Firewall",
SituationId="1004",
Situation="FW_Related-Connection",
EventId="7307448264968634400",
Service="TCP/51332"

FIA_AFL.1
Auditable event Unsuccessful login attempt limit is met or exceeded
Prevent the offending remote Administrator from successfully authenticating until an Administrator defined time period has elapsed

Timestamp="2025-03-17 02:38:50",
NodeId="192.0.2.2",
CompId="cc-smca-mgmt",
InfoMsg="Too many login failures in 30 mins  account is disabled. ERROR: Authentication failed. The user name or password might be incorrect. Verify that the address of the server is correct and that it is running properly. ",
SenderType="Management Server",
EventId="803323531923306073",
UserOriginator="System",
ClientIpAddress="192.0.2.2",
TypeDescription="stonegate.admin.disabled",
Result="Fail",
ObjectName="secadmin"
Timestamp="2025-03-17 02:35:09",
NodeId="192.0.2.2",
CompId="cc-smca-mgmt",
InfoMsg="Too many login failures from same source  wait 30 min to retry. ERROR: Authentication failed. The user name or password might be incorrect. Verify that the address of the server is correct and that it is running properly. ",
SenderType="Management Server",
EventId="803323531923306004",
UserOriginator="System",
ClientIpAddress="192.168.200.10",
TypeDescription="stonegate.admin.login",
Result="Fail",
ObjectName="Unknown user"

FIA_UAU_EXT.2, FIA_UIA_EXT.1
Auditable event All use of identification and authentication mechanism
Local session identification and authentication failures

Timestamp="2025-03-23 12:34:35",
NodeId="127.0.0.1",Type="Notification",
CompId="3",
InfoMsg="Mar 23 12:34:35 cc-audit-smca login: pam_unix(login:auth): check pass; user unknown",
ReceptionTime="2025-03-23 12:34:35",
SenderType="Third Party Device",
EventId="11720"
Timestamp="2025-03-23 12:34:35",
NodeId="127.0.0.1",
Type="Notification",
CompId="3",
InfoMsg="Mar 23 12:34:35 cc-audit-smca login: pam_unix(login:auth): authentication failure; logname= uid=0 euid=0 tty=/dev/tty1 ruser= rhost=",
ReceptionTime="2025-03-23 12:34:35",
SenderType="Third Party Device",
EventId="11721"

Local session identification and authentication failures (continue)

Timestamp="2025-03-23 12:34:35",
NodeId="127.0.0.1",
Type="Notification",
CompId="3",
InfoMsg="Mar 23 12:34:35 cc-audit-smca login: pam_faillock(login:auth): User unknown",
ReceptionTime="2025-03-23 12:34:35",
SenderType="Third Party Device",
EventId="11722"
Timestamp="2025-03-23 12:34:36",
NodeId="127.0.0.1",
Type="Notification",
CompId="3",
InfoMsg="Mar 23 12:34:36 cc-audit-smca login: FAILED LOGIN SESSION FROM tty1 FOR noadmin  Permission denied",
ReceptionTime="2025-03-23 12:34:36",
SenderType="Third Party Device",
EventId="11724"

Local session identification and authentication failures

(Continued)

Timestamp="2025-03-23 12:43:20",
NodeId="127.0.0.1",
Type="Notification",
CompId="3",
InfoMsg="Mar 23 12:43:20 cc-audit-smca unix_chkpwd[327750]: password check failed for user (radmin)",
ReceptionTime="2025-03-23 12:43:20",
SenderType="Third Party Device",
EventId="11738"
Timestamp="2025-03-23 12:43:20",
NodeId="127.0.0.1",
Type="Notification",
CompId="3",
InfoMsg="Mar 23 12:43:20 cc-audit-smca login: pam_unix(login:auth): authentication failure; logname= uid=0 euid=0 tty=/dev/tty1 ruser= rhost=
user=radmin",
ReceptionTime="2025-03-23 12:43:20",
SenderType="Third Party Device",
EventId="11739"
Timestamp="2025-03-23 12:43:22",
NodeId="127.0.0.1",
Type="Notification",
CompId="3",
InfoMsg="Mar 23 12:43:22 cc-audit-smca login: FAILED LOGIN SESSION FROM tty1 FOR radmin  Permission denied",
ReceptionTime="2025-03-23 12:43:22",
SenderType="Third Party Device",
EventId="11741"

Local session successful identification and authentication

Timestamp="2025-03-23 11:37:11",
NodeId="127.0.0.1",
Type="Notification",
CompId="3",
InfoMsg="Mar 23 11:37:11 cc-audit-smca login: pam_unix(login:session): session opened for user radmin(uid=1000) by radmin(uid=0)",
ReceptionTime="2025-03-23 11:37:11",
SenderType="Third Party Device",
EventId="11465"
Timestamp="2025-03-23 11:37:11",
NodeId="127.0.0.1",
Type="Notification",
CompId="3",
InfoMsg="Mar 23 11:37:11 cc-audit-smca login: LOGIN ON tty1 BY radmin",
ReceptionTime="2025-03-23 11:37:11",
SenderType="Third Party Device",
EventId="11468"

Remote session identification and authentication failures

Timestamp="2025-03-17 02:38:50",
NodeId="192.0.2.2",
CompId="cc-smca-mgmt",
InfoMsg="Login failed for user secadmin. ERROR: Authentication failed. The user name or password might be incorrect. Verify that the address of the server is correct and that it is running properly. ",
SenderType="Management Server",
EventId="803323531923306074",
UserOriginator="System",
ClientIpAddress="192.168.200.10",
TypeDescription="stonegate.admin.login",
Result="Fail",
ObjectName="secadmin;Shared Domain"
Timestamp="2025-03-17 02:43:58",
NodeId="192.0.2.2",
CompId="cc-smca-mgmt",
InfoMsg="Login attempt for unknown user badadmin",
SenderType="Management Server",
EventId="803323531923306112",
UserOriginator="System",
ClientIpAddress="192.168.200.10",
TypeDescription="stonegate.admin.login",
Result="Fail",
ObjectName="Unknown user"

Remote session identification and authentication succeeds

Timestamp="2025-03-18 13:44:10",
NodeId="192.0.2.2",
CompId="Management Server",
InfoMsg="Login succeeded for user test00 in domain Shared Domain",
SenderType="Management Server",
EventId="2987302565009424645",
UserOriginator="System",
ClientIpAddress="192.0.2.1",
TypeDescription="stonegate.admin.login",
Result="Success",
ObjectName="test00;Shared Domain"

FIA_X509_EXT.1
Auditable event Unsuccessful attempt to validate a certificate
Unsuccessful attempt to validate a certificate

Timestamp="2025-03-14 11:55:05",
NodeId="192.0.2.2",
CompId="Management Server",
InfoMsg="TLS Certificate validation failed.Protocol = TLSv1.2  Peer = [host=192.0.2.10  port=2055]  Local = [host=Unknown  port=Unknown] ERROR: certificate expired on 20200102080000GMT+00:00",
SenderType="Management Server",
EventId="1476204865502838959",
UserOriginator="System",
ClientIpAddress="192.0.2.10",
TypeDescription="stonegate.trusted.certificate.validation.failure",
Result="Fail"
Timestamp="2025-03-14 11:55:05",
NodeId="192.0.2.2",
CompId="Management Server",
InfoMsg="TLS Connection failed : Protocol = NONE  Peer = [host=192.0.2.10  port=2055]  Local = [host=192.0.2.2  port=35696] ERROR: Syslog authentication failed. [/192.0.2.10:2055] Details: certificate expired on 20200102080000GMT+00:00",
SenderType="Management Server",
EventId="1476204865502838960",
UserOriginator="System",
ClientIpAddress="192.0.2.10",
TypeDescription="stonegate.trusted.connection.failure",
Result="Fail"
Timestamp="2025-03-19 11:19:42",
NodeId="192.0.2.2",
CompId="Management Server",
InfoMsg="TLS Certificate validation failed.Protocol = TLSv1.2  Peer = [host=192.0.2.10  port=2055]  Local = [host=Unknown  port=Unknown] ERROR: Server Identity Check Failed",
SenderType="Management Server",
EventId="3322506096534356246",
UserOriginator="System",
ClientIpAddress="192.0.2.10",
TypeDescription="stonegate.trusted.certificate.validation.failure",
Result="Fail"
Timestamp="2025-03-19 11:19:42",
NodeId="192.0.2.2",
CompId="Management Server",
InfoMsg="TLS Connection failed : Protocol = NONE  Peer = [host=192.0.2.10  port=2055]  Local = [host=192.0.2.2  port=45304] ERROR: Syslog authentication failed. [/192.0.2.10:2055] Details: Server Identity Check Failed",
SenderType="Management Server",
EventId="3322506096534356257",
UserOriginator="System",
ClientIpAddress="192.0.2.10",
TypeDescription="stonegate.trusted.connection.failure",
Result="Fail"

FIA_X509_EXT.1/ITT
Auditable event Unsuccessful attempt to validate a certificate
Unsuccessful attempt to validate a certificate (Security Engine)

Timestamp="2025-03-17 17:26:54",
LogId="1876",
NodeId="192.0.2.4",
Facility="Management",
Type="Warning",
Src="192.0.2.2",
Dst="192.0.2.4",
CompId="ngfw node 1",
InfoMsg="Revocation check failed with status: enoent  state: cert_revoked  path_not_verified  certificate identity: Subject:C=FR  CN=MgtSrvCert|Issuer:C=FI  CN=ext_pki-ocsp-ic certificate|Serial:0x1",
ReceptionTime="2025-03-17 17:26:55",
SenderType="Firewall",
SituationId="79059",
Situation="TLS_Certificate-Verify-Failed",
EventId="7307452383842273108"
Timestamp="2025-03-17 17:26:54",
LogId="1877",
NodeId="192.0.2.4",
Facility="Management",
Type="Error",
CompId="ngfw node 1",
InfoMsg="Dropping client 192.0.2.4:56999-192.0.2.2:8906 due to validation failure",
ReceptionTime="2025-03-17 17:26:55",
SenderType="Firewall",
EventId="7307452383842273109"
Timestamp="2025-03-17 17:26:54",
LogId="1878",
NodeId="192.0.2.4",
Facility="Management",
Type="Notification",
CompId="ngfw node 1",
InfoMsg="TLS: Connection disconnect (DNS:ManagementServer  192.0.2.2)",
ReceptionTime="2025-03-17 17:26:55",
SenderType="Firewall",
SituationId="78002",
Situation="TLS connection state",
EventId="7307452383842273110"
Timestamp="2025-03-17 17:27:44",
LogId="5716",
NodeId="192.0.2.4",
Facility="Management",
Type="Warning",
Src="192.0.2.2",
Dst="192.0.2.4",
CompId="ngfw node 1",
InfoMsg="Revocation check failed with status: enoent  state: cert_revoked  path_not_verified  certificate identity: Subject:C=FI  CN=ext_pki-ocsp-ic certificate|Issuer:C=FI  L=Helsinki  CN=ext_pki-ocsp-ca certificate|Serial:0x1",
ReceptionTime="2025-03-17 17:27:44",
SenderType="Firewall",
SituationId="79059",
Situation="TLS_Certificate-Verify-Failed",
EventId="7307452590000707156"

Unsuccessful attempt to validate a certificate (Security Engine

(continued)

)

Timestamp="2025-03-17 17:27:44",
LogId="5717",
NodeId="192.0.2.4",
Facility="Management",
Type="Error",
CompId="ngfw node 1",
InfoMsg="Dropping client 192.0.2.4:54419-192.0.2.2:8906 due to validation failure",
ReceptionTime="2025-03-17 17:27:44",
SenderType="Firewall",
EventId="7307452590000707157"
Timestamp="2025-03-17 17:27:44",
LogId="5718",
NodeId="192.0.2.4",
Facility="Management",
Type="Notification",
CompId="ngfw node 1",
InfoMsg="TLS: Connection disconnect (DNS:ManagementServer  192.0.2.2)",
ReceptionTime="2025-03-17 17:27:44",
SenderType="Firewall",
SituationId="78002",
Situation="TLS connection state",
EventId="7307452590000707158"

Unsuccessful attempt to validate a certificate (SMC)

Timestamp="2025-03-17 16:48:14",
NodeId="192.0.2.2",
CompId="Management Server",
InfoMsg="TLS Connection failed : Protocol = NONE  Peer = [host=192.0.2.2  port=57136]  Local = [port=8907] ERROR: Failed to check certificate Details: Certificate Error:  The Certificate (subjectDN=CN=LogServer 192.0.2.2  serialNumber=1):  Certificate has been revoked  reason: KEY_COMPROMISE  revocation date: Mon Mar 17 16:47:51 GMT 2025  authority: CN=OCSP Responder  L=Helsinki  C=FI  extension OIDs: []",
SenderType="Management Server",
EventId="2665307750136807579",
UserOriginator="System",
ClientIpAddress="192.0.2.2",
TypeDescription="stonegate.trusted.connection.failure",
Result="Fail"

FMT_MOF.1/ManualUpdate
Auditable event Any attempt to initiate a manual update
Any attempt to initiate a manual update

Timestamp="2025-03-17 03:31:03",
NodeId="192.0.2.2",
CompId="cc-smca-mgmt",
InfoMsg="You do not have the required permissions to perform this action. Details: You do not have the required permissions to manage Updates and Upgrades.  You are missing the following permissions:  - Manage Updates and Upgrades   Change your permissions or contact an administrator with the appropriate permissions to resolve this issue.",
SenderType="Management Server",
EventId="803323531923306234",
UserOriginator="smcoperator",
ClientIpAddress="192.168.200.10",
TypeDescription="stonegate.mgtserver.upgrade.import",
Result="Fail",
ObjectName="Engine Upgrade sg_engine_7.3.0.31055_x86-64-small.zip"
Timestamp="2025-07-08 12:15:39",
NodeId="192.0.2.2",
CompId="cc-smca-mgmt",
InfoMsg="You do not have the required permissions to perform this action. Details: You do not have the required permissions to manage Updates and Upgrades.  You are missing the following permissions:  - Manage Updates and Upgrades   Change your permissions or contact an administrator with the appropriate permissions to resolve this issue.",
SenderType="Management Server",
EventId="7625591619458170908",
UserOriginator="smcoperator",
ClientIpAddress="192.168.200.10",
TypeDescription="stonegate.mgtserver.appliance_patch.import",
Result="Fail",
ObjectName="SMC Appliance Patch 7.3.1U001.sap"

FMT_MOF.1/Functions
Auditable event Modification of the behavior of the audit functionality when Local Audit Storage Space is full
Modification of the behavior of the audit functionality when Local Audit Storage Space is full

Timestamp="2025-03-17 02:55:20",
NodeId="192.0.2.2",
CompId="cc-smca-mgmt",
InfoMsg="log_disk_space_handling_mode has been modified (overwrite_oldest -> stop_receiving).",
SenderType="Management Server",
EventId="803323531923306136",
UserOriginator="radmin",
ClientIpAddress="192.168.200.1",
TypeDescription="stonegate.object.update.details",
Result="Success",
ObjectName="cc-smca-mgmt"

Modification of the behavior of the transmission of audit data to an external IT entity

Timestamp="2025-03-17 16:57:55",
NodeId="192.0.2.2",
CompId="Management Server",
InfoMsg="A new log forward rule was created with  types to host syslog_server (port 2055).",
SenderType="Management Server",
EventId="2665307750136807974",
UserOriginator="test00",
ClientIpAddress="192.0.2.1",
TypeDescription="stonegate.log.forward.new",
Result="Success",
ObjectName="Management Server"

Modification of the behavior of the handling of audit data

Timestamp="2025-03-17 03:04:50",
NodeId="192.0.2.2",
CompId="cc-smca-mgmt",
InfoMsg="storable_task_definition element has been created.",
SenderType="Management Server",
EventId="803323531923306146",
UserOriginator="radmin",
ClientIpAddress="192.168.200.1",
TypeDescription="stonegate.object.insert",
Result="Success",
ObjectName="Delete old Audit data"
Timestamp="2025-03-17 03:06:22",
NodeId="192.0.2.2",
CompId="cc-smca-mgmt",
InfoMsg="task_schedule element has been created.",
SenderType="Management Server",
EventId="803323531923306147",
UserOriginator="radmin",
ClientIpAddress="192.168.200.1",
TypeDescription="stonegate.object.insert",
Result="Success",
ObjectName="(Schedule) Delete old Audit data"

FPT_ITT.1
Auditable event TLS communication between the distributed TOE components
Initiation of the trusted channel (Security Engine)

Timestamp="2025-03-17 16:40:31",
LogId="2808",
NodeId="192.0.2.4",
Facility="Management",
Type="Notification",
CompId="ngfw node 1",
InfoMsg="TLS: Accepted connection (DNS:ManagementServer  192.0.2.2)",
ReceptionTime="2025-03-17 16:40:32",
SenderType="Firewall",
SituationId="78002",
Situation="TLS connection state",
EventId="7307440710121163512"

Termination of the trusted channel (Security Engine)

Timestamp="2025-03-17 16:40:44",
LogId="2822",
NodeId="192.0.2.4",
Facility="Management",
Type="Notification",
CompId="ngfw node 1",
InfoMsg="TLS: Connection closed (DNS:ManagementServer  192.0.2.2)",
ReceptionTime="2025-03-17 16:40:45",
SenderType="Firewall",
SituationId="78002",
Situation="TLS connection state",
EventId="7307440765955738374"

Failure of the trusted channel functions (Security Engine)

Timestamp="2025-03-17 17:22:56",
LogId="1981",
NodeId="192.0.2.4",
Facility="Management",
Type="Error",
CompId="ngfw node 1",
InfoMsg="no shared cipher",
ReceptionTime="2025-03-17 17:22:57",
SenderType="Firewall",
SituationId="9005",
Situation="FW_Communication-Communication-Error",
EventId="7307451383114893245"
Timestamp="2025-03-17 17:22:56",
LogId="1982",
NodeId="192.0.2.4",
Facility="Management",
Type="Notification",
CompId="ngfw node 1",
InfoMsg="TLS: Couldn't accept TLS connection: -3 (DNS:ManagementServer  192.0.2.2)",
ReceptionTime="2025-03-17 17:22:57",
SenderType="Firewall",
SituationId="78002",
Situation="TLS connection state",
EventId="7307451383114893246"

Initiation of the trusted channel (SMC)

Timestamp="2025-03-18 13:37:40",
NodeId="192.0.2.2",
CompId="Management Server",
InfoMsg="TLS Connection started : Protocol = TLSv1.2  Peer = [host=192.0.2.4  port=49771]  Local = [host=192.0.2.2  port=8906]",
SenderType="Management Server",
EventId="2987302565009424590",
UserOriginator="System",
ClientIpAddress="192.0.2.4",
TypeDescription="stonegate.trusted.connection.start",
Result="Success"

Termination of the trusted channel (SMC)

Timestamp="2025-03-18 13:37:40",
NodeId="192.0.2.2",
CompId="Management Server",
InfoMsg="TLS Connection ended : Protocol = TLSv1.2  Peer = [host=192.0.2.4  port=49771]  Local = [port=8906]",
SenderType="Management Server",
EventId="2987302565009424593",
UserOriginator="System",
ClientIpAddress="192.0.2.4",
TypeDescription="stonegate.trusted.connection.end",
Result="Success"

Failure of the trusted channel functions (SMC)

Timestamp="2025-03-17 16:57:48",
NodeId="192.0.2.2",
CompId="Management Server",
InfoMsg="TLS Connection failed : Protocol = NONE  Peer = [host=192.0.2.2  port=54902]  Local = [port=8907] ERROR: Failed to check certificate Details: Certificate Error:  The Certificate (subjectDN=CN=LogServer 192.0.2.2  serialNumber=4):  Responder's certificate not valid for signing OCSP responses",
SenderType="Management Server",
EventId="2665307750136807967",
UserOriginator="System",
ClientIpAddress="192.0.2.2",
TypeDescription="stonegate.trusted.connection.failure",
Result="Fail"

FPT_TUD_EXT.1
Auditable event Initiation of update
Verification of image

(SMC)

Timestamp="2025-07-11 08:42:45",
NodeId="127.0.0.1",
Type="Notification",
CompId="3",
InfoMsg="Jul 11 08:42:45 cc-smca AMBR_LOGGER.log : INFO : pid=2482 : Verified patch 7.3.0U001.",
ReceptionTime="2025-07-11 08:42:45",
SenderType="Third Party Device",
EventId="2762"

SMC Appliance update

Timestamp="2025-07-11 10:06:27",
NodeId="127.0.0.1",
Type="Notification",
CompId="3",
InfoMsg="Jul 11 10:06:27 cc-smca sudo: sgadmin : PWD=/usr/local/forcepoint/smc ; USER=radmin ; GROUP=smca_priv ; COMMAND=/usr/bin/sudo /usr/bin/ambr-load -f /usr/local/forcepoint/smc/7.3.0U001.sap",
ReceptionTime="2025-07-11 10:06:27",
SenderType="Third Party Device",
EventId="3241"
Timestamp="2025-07-11 10:06:27",
NodeId="127.0.0.1",
Type="Notification",
CompId="3",
InfoMsg="Jul 11 10:06:27 cc-smca sudo: radmin : PWD=/usr/local/forcepoint/smc ; USER=root ; COMMAND=/usr/bin/ambr-load -f /usr/local/forcepoint/smc/7.3.0U001.sap",
ReceptionTime="2025-07-11 10:06:27",
SenderType="Third Party Device",
EventId="3269"

Successful SMC update

Timestamp="2025-07-11 11:03:16",
NodeId="127.0.0.1",
Type="Notification",
CompId="3",
InfoMsg="Jul 11 11:03:16 cc-smca sudo: radmin : TTY=tty1 ; PWD=/home/radmin ; USER=root ; COMMAND=/usr/bin/ambr-install --no-prompt 7.3.0U001",
ReceptionTime="2025-07-11 11:03:16",
SenderType="Third Party Device",
EventId="3462"
Timestamp="2025-07-11 11:03:57",
NodeId="127.0.0.1",
Type="Notification",
CompId="3",
InfoMsg="Jul 11 11:03:57 cc-smca AMBR_LOGGER.log : INFO : pid=7527 : Verified patch 7.3.0U001.",
ReceptionTime="2025-07-11 11:03:57",
SenderType="Third Party Device",
EventId="3466"
Timestamp="2025-07-11 11:03:57",
NodeId="127.0.0.1",
Type="Notification",
CompId="3",
InfoMsg="Jul 11 11:03:57 cc-smca AMBR_LOGGER.log : INFO : pid=7527 : Creating recovery snapshot...",
ReceptionTime="2025-07-11 11:03:57",
SenderType="Third Party Device",
EventId="3467"
Timestamp="2025-07-11 11:03:58",
NodeId="127.0.0.1",
Type="Notification",
CompId="3",
InfoMsg="Jul 11 11:03:58 cc-smca AMBR_LOGGER.log : INFO : pid=7527 : Created recovery snapshot.",
ReceptionTime="2025-07-11 11:03:58",
SenderType="Third Party Device",
EventId="3474"
Timestamp="2025-07-11 11:03:58",
NodeId="127.0.0.1",
Type="Notification",
CompId="3",
InfoMsg="Jul 11 11:03:58 cc-smca AMBR_LOGGER.log : INFO : pid=7527 : Creating configuration backup...",
ReceptionTime="2025-07-11 11:03:58",
SenderType="Third Party Device",
EventId="3475"
Timestamp="2025-07-11 11:04:26",
NodeId="127.0.0.1",
Type="Notification",
CompId="3",
InfoMsg="Jul 11 11:04:26 cc-smca AMBR_LOGGER.log : INFO : pid=7527 : Created configuration backup.",
ReceptionTime="2025-07-11 11:04:26",
SenderType="Third Party Device",
EventId="3494"
Timestamp="2025-07-11 11:04:26",
NodeId="127.0.0.1",
Type="Notification",
CompId="3",
InfoMsg="Jul 11 11:04:26 cc-smca AMBR_LOGGER.log : INFO : pid=7527 : Installing patch(es): 7.3.0U001",
ReceptionTime="2025-07-11 11:04:26",
SenderType="Third Party Device",
EventId="3495"
Timestamp="2025-07-11 11:04:26",
NodeId="127.0.0.1",
Type="Notification",
CompId="3",
InfoMsg="Jul 11 11:04:26 cc-smca AMBR_LOGGER.log : INFO : pid=7527 : Installing patch 7.3.0U001...",
ReceptionTime="2025-07-11 11:04:26",
SenderType="Third Party Device",
EventId="3496"
Timestamp="2025-07-11 11:04:34",
NodeId="127.0.0.1",
Type="Notification",
CompId="3",
InfoMsg="Jul 11 11:04:34 cc-smca AMBR_LOGGER.log : INFO : pid=7527 : Installed patch 7.3.0U001.",
ReceptionTime="2025-07-11 11:04:34",
SenderType="Third Party Device",
EventId="3501"
Timestamp="2025-07-11 11:04:34",
NodeId="127.0.0.1",
Type="Notification",
CompId="3",
InfoMsg="Jul 11 11:04:34 cc-smca AMBR_LOGGER.log : INFO : pid=7527 : Performing post-installation cleanup tasks...",
ReceptionTime="2025-07-11 11:04:34",
SenderType="Third Party Device",
EventId="3502"
Timestamp="2025-07-11 11:04:35",
NodeId="127.0.0.1",
Type="Notification",
CompId="3",
InfoMsg="Jul 11 11:04:35 cc-smca AMBR_LOGGER.log : INFO : pid=7527 : Successfully installed patch(es): 7.3.0U001.",
ReceptionTime="2025-07-11 11:04:35",
SenderType="Third Party Device",
EventId="3503"
Timestamp="2025-07-11 11:04:35",
NodeId="127.0.0.1",
Type="Notification",
CompId="3",
InfoMsg="Jul 11 11:04:35 cc-smca AMBR_LOGGER.log : INFO : pid=7527 : Rebooting system to complete installation.",
ReceptionTime="2025-07-11 11:04:35",
SenderType="Third Party Device",
EventId="3506"

Failed SMC Appliance update

Timestamp="2025-07-09 11:37:48",
NodeId="127.0.0.1",
Type="Notification",
CompId="3",
InfoMsg="Jul 9 11:37:48 cc-smca AMBR_LOGGER.log : ERROR : pid=17801 : sap signature file /var/tmp/tmpf8kpzemo/6.11.0U001-unsigned.sap.sig does not exist.",
ReceptionTime="2025-07-09 11:37:48",
SenderType="Third Party Device",
EventId="4378"
Timestamp="2025-07-09 11:37:48",
NodeId="127.0.0.1",
Type="Notification",
CompId="3",
InfoMsg="Jul 9 11:37:48 cc-smca AMBR_LOGGER.log : ERROR : pid=17801 : sap signature file /var/tmp/tmpf8kpzemo/6.11.0U001-unsigned.sap.sig does not exist.#012Traceback (most recent call last):#012 File 'build/lib/ambr/client/load/application.py'  line 118  in _load_local#012 File 'build/lib/ambr/client/load/application.py'  line 214  in _fetch_metadata#012 File 'build/lib/ambr/common/crypto.py'  line 240  in verify_package#012 File 'build/lib/ambr/common/crypto.py'  line 347  in verify_package20#012ValueError: sap signature file /var/tmp/tmpf8kpzemo/6.11.0U001-unsigned.sap.sig does not exist.",
ReceptionTime="2025-07-09 11:37:48",
SenderType="Third Party Device",
EventId="4379"
Timestamp="2025-07-09 11:37:48",
NodeId="127.0.0.1",
Type="Notification",
CompId="3",
InfoMsg="Jul 9 11:37:48 cc-smca AMBR_LOGGER.log : ERROR : pid=17801 : Failed to load: /usr/local/forcepoint/smc/6.11.0U001-unsigned.sap",
ReceptionTime="2025-07-09 11:37:48",
SenderType="Third Party Device",
EventId="4380"
Timestamp="2025-07-09 11:37:49",
NodeId="192.0.2.22",
CompId="cc-smca-mgmt",
InfoMsg="ERROR: sap signature file /var/tmp/tmpf8kpzemo/6.11.0U001-unsigned.sap.sig does not exist.ERROR: Unable to load /usr/local/forcepoint/smc/6.11.0U001-unsigned.sap to /var/ambr/downloaded.ERROR: sap signature file /var/tmp/tmpf8kpzemo/6.11.0U001-unsigned.sap.sig does not exist.ERROR: Failed to load: /usr/local/forcepoint/smc/6.11.0U001-unsigned.sap",
SenderType="Management Server",
EventId="7625591619458170995",
UserOriginator="radmin",
ClientIpAddress="192.168.200.10",
TypeDescription="stonegate.mgtserver.appliance_patch.import",
Result="Fail",
ObjectName="SMC Appliance Patch 6.11.0U001-unsigned.sap"
Timestamp="2025-07-10 08:28:54",
NodeId="127.0.0.1",
Type="Notification",
CompId="3",
InfoMsg="Jul 10 08:28:54 cc-smca AMBR_LOGGER.log : ERROR : pid=27616 : Unable to get issuer certificate for 'C=US  ST=TX  O=Forcepoint  OU=NGFW  CN=NGFW Updates 2020'#012Traceback (most recent call last):#012 File 'build/lib/ambr/common/crypto.py'  line 195  in verify_signer#012 File 'build/lib/ambr/common/crypto.py'  line 140  in verify_chain#012ValueError: Unable to get issuer certificate for 'C=US  ST=TX  O=Forcepoint  OU=NGFW  CN=NGFW Updates 2020'",
ReceptionTime="2025-07-10 08:28:54",
SenderType="Third Party Device",
EventId="5111"
Timestamp="2025-07-10 08:28:54",
NodeId="127.0.0.1",
Type="Notification",
CompId="3",
InfoMsg="Jul 10 08:28:54 cc-smca AMBR_LOGGER.log : ERROR : pid=27616 : No valid signer certificates for '/var/tmp/tmpre6ekjn_/6.11.0U001-corrupted.sap'#012Traceback (most recent call last):#012 File 'build/lib/ambr/client/load/application.py'  line 118  in _load_local#012 File 'build/lib/ambr/client/load/application.py'  line 214  in _fetch_metadata#012 File 'build/lib/ambr/common/crypto.py'  line 238  in verify_package#012 File 'build/lib/ambr/common/crypto.py'  line 303  in verify_package10#012 File 'build/lib/ambr/common/crypto.py'  line 283  in verify_package_common#012ValueError: No valid signer certificates for '/var/tmp/tmpre6ekjn_/6.11.0U001-corrupted.sap'",
ReceptionTime="2025-07-10 08:28:54",
SenderType="Third Party Device",
EventId="5112"
Timestamp="2025-07-10 08:28:54",
NodeId="127.0.0.1",
Type="Notification",
CompId="3",
InfoMsg="Jul 10 08:28:54 cc-smca AMBR_LOGGER.log : ERROR : pid=27616 : Failed to load: /usr/local/forcepoint/smc/6.11.0U001-corrupted.sap",
ReceptionTime="2025-07-10 08:28:54",
SenderType="Third Party Device",
EventId="5113"
Timestamp="2025-07-10 08:28:55",
NodeId="192.0.2.22",
CompId="cc-smca-mgmt",
InfoMsg="ERROR: Unable to get issuer certificate for 'C=US  ST=TX  O=Forcepoint  OU=NGFW  CN=NGFW Updates 2018'ERROR: Unable to get issuer certificate for 'C=US  ST=TX  O=Forcepoint  OU=NGFW  CN=NGFW Updates 2020'ERROR: Unable to load /usr/local/forcepoint/smc/6.11.0U001-corrupted.sap to /var/ambr/downloaded.ERROR: No valid signer certificates for '/var/tmp/tmpre6ekjn_/6.11.0U001-corrupted.sap'ERROR: Failed to load: /usr/local/forcepoint/smc/6.11.0U001-corrupted.sap",
SenderType="Management Server",
EventId="7625591619458171068",
UserOriginator="radmin",
ClientIpAddress="192.168.200.10",
TypeDescription="stonegate.mgtserver.appliance_patch.import",
Result="Fail",ObjectName="SMC Appliance Patch 6.11.0U001-corrupted.sap"

Verification of image

(Security Engine)

Timestamp="2025-04-09 13:26:09",
LogId="1245563",
NodeId="192.0.2.4",
Facility="Management",
Type="Notification",
CompId="cc-ngfw-1 node 1",
InfoMsg="Engine upgrade: Engine image signature verified",
ReceptionTime="2025-04-09 13:26:09",
SenderType="Firewall",
SituationId="40015",
Situation="System_Engine_Upgrade-Succeeded",
EventId="7315726719943639419"

Initiation of Security Engine Engine update

Timestamp="2025-04-09 13:25:30",
NodeId="192.0.2.2",
CompId="cc-smca-mgmt",
InfoMsg="Image sg_engine_7.3.0.31049_x86-64-small.zip",
SenderType="Management Server",
EventId="8926881974736512916",
UserOriginator="radmin",
ClientIpAddress="192.168.200.1",
TypeDescription="stonegate.engine.upgrade.start",
Result="Success",
ObjectName="cc-ngfw-1 node 1"

Result of the Security Engine Engine update attempt

Timestamp="2025-04-09 13:27:39",
NodeId="192.0.2.2",
CompId="cc-smca-mgmt",
InfoMsg="Image StoneGate firewall(x86-64-small) version 7.3 #31049",
SenderType="Management Server",
EventId="8926881974736512926",
UserOriginator="radmin",
ClientIpAddress="192.168.200.1",
TypeDescription="stonegate.engine.upgrade.end",
Result="Success",
ObjectName="cc-ngfw-1 node 1"

Failed Security Engine Engine update

Timestamp="2025-04-14 13:45:05",
NodeId="192.0.2.2",
CompId="cc-smca-mgmt",
InfoMsg="Signature verification failed for the Update Package or Engine Upgrade Trust anchor for certification path not found.",
SenderType="Management Server",
EventId="2695119513275340574",
UserOriginator="radmin",
ClientIpAddress="192.168.200.1",
TypeDescription="stonegate.mgtserver.upgrade.import",
Result="Fail",
ObjectName="Engine Upgrade sg_engine_6.11.0.27009.invalid.1_x86-64-small.zip"

FTA_SSL.3
Auditable event The termination of a remote session by session locking mechanism
Termination of a remote session by session locking mechanism

Timestamp="2025-04-07 13:39:28",
NodeId="192.0.2.2",
CompId="cc-smca-mgmt",
InfoMsg="Management Client window closed due to idle timeout.",
SenderType="Management Server",
EventId="1183832478725439491",
UserOriginator="radmin",
ClientIpAddress="192.168.200.1",
TypeDescription="stonegate.session.terminated",
Result="Success",
ObjectName="radmin"
Timestamp="2025-04-07 13:39:28",
NodeId="192.0.2.2",
CompId="cc-smca-mgmt",
InfoMsg="Logout succeeded for user radmin.",
SenderType="Management Server",
EventId="8926881974736507459",
UserOriginator="System",
ClientIpAddress="192.168.200.1",
TypeDescription="stonegate.admin.logout",
Result="Success",
ObjectName="radmin"

FTA_SSL.4
Auditable event The termination of an interactive session
Termination of local administrative session

Timestamp="2025-04-04 14:06:56",
NodeId="127.0.0.1",
Type="Notification",
CompId="3",
InfoMsg="Apr 4 14:06:56 cc-smca login: pam_unix(login:session): session closed for user radmin",
ReceptionTime="2025-04-04 14:06:56",
SenderType="Third Party Device",
EventId="6132"

Termination of remote administrative session

Timestamp="2025-03-17 16:53:03",
NodeId="192.0.2.2",
CompId="Management Server",
InfoMsg="Logout succeeded for user test00.",
SenderType="Management Server",
EventId="2665307750136807783",
UserOriginator="System",
ClientIpAddress="127.0.0.1",
TypeDescription="stonegate.admin.logout",
Result="Success",
ObjectName="test00"

FTA_SSL_EXT.1
Auditable event Local session termination
Local session termination

Timestamp="2025-04-04 14:06:56",
NodeId="127.0.0.1",
Type="Notification",
CompId="3",
InfoMsg="Apr 4 14:06:56 cc-smca audisp-syslog: type=CRED_DISP msg=audit(1743775616.013:715): pid=75528 uid=0 auid=1000 ses=8 subj=system_u:system_r:local_login_t:s0-s0:c0.c1023 msg='op=PAM:setcred grantors=pam_unix pam_securetty acct='radmin' exe='/usr/bin/login' hostname=cc-smca addr=? terminal=/dev/tty1 res=success' UID='root' AUID='radmin'",
ReceptionTime="2025-04-04 14:06:56",
SenderType="Third Party Device",
EventId="6131"
Timestamp="2025-04-04 14:06:56",
NodeId="127.0.0.1",
Type="Notification",
CompId="3",
InfoMsg="Apr 4 14:06:56 cc-smca login: pam_unix(login:session): session closed for user radmin",
ReceptionTime="2025-04-04 14:06:56",
SenderType="Third Party Device",
EventId="6132"
Timestamp="2025-04-04 14:06:56",
NodeId="127.0.0.1",
Type="Notification",
CompId="3",
InfoMsg="Apr 4 14:06:56 cc-smca audisp-syslog: type=SYSCALL msg=audit(1743775616.013:716): arch=c000003e syscall=188 success=yes exit=0 a0=562f5a18e350 a1=7fb6549ba1c5 a2=562f5a1b22a0 a3=22 items=1 ppid=1 pid=75528 auid=1000 uid=0 gid=498 euid=0 suid=0 fsuid=0 egid=498 sgid=498 fsgid=498 tty=(none) ses=8 comm='login' exe='/usr/bin/login' subj=system_u:system_r:local_login_t:s0-s0:c0.c1023 key='perm_mod' ARCH=x86_64 SYSCALL=setxattr AUID='radmin' UID='root' GID='smca_admin' EUID='root' SUID='root' FSUID='root' EGID='smca_admin' SGID='smca_admin' FSGID='smca_admin'",
ReceptionTime="2025-04-04 14:06:56",
SenderType="Third Party Device",
EventId="6133"
Timestamp="2025-04-04 14:06:56",
NodeId="127.0.0.1",
Type="Notification",
CompId="3",
InfoMsg="Apr 4 14:06:56 cc-smca audisp-syslog: type=PATH msg=audit(1743775616.013:716): item=0 name='/dev/tty1' inode=20 dev=00:05 mode=020620 ouid=1000 ogid=5 rdev=04:01 obj=unconfined_u:object_r:user_tty_device_t:s0 nametype=NORMAL cap_fp=0 cap_fi=0 cap_fe=0 cap_fver=0 cap_frootid=0 OUID='radmin' OGID='tty'",
ReceptionTime="2025-04-04 14:06:56",
SenderType="Third Party Device",
EventId="6135"
Timestamp="2025-04-04 14:06:56",
NodeId="127.0.0.1",
Type="Notification",
CompId="3",
InfoMsg="Apr 4 14:06:56 cc-smca systemd-logind[1141]: Session 8 logged out. Waiting for processes to exit.",
ReceptionTime="2025-04-04 14:06:56",
SenderType="Third Party Device",
EventId="6137"

Local session termination

(continued)

Timestamp="2025-04-04 14:06:56",
NodeId="127.0.0.1",
Type="Notification",
CompId="3",
InfoMsg="Apr 4 14:06:56 cc-smca audisp-syslog: type=USER_END msg=audit(1743775616.015:717): pid=75528 uid=0 auid=1000 ses=8 subj=system_u:system_r:local_login_t:s0-s0:c0.c1023 msg='op=PAM:session_close grantors=pam_selinux pam_loginuid pam_selinux pam_namespace pam_keyinit pam_keyinit pam_limits pam_systemd pam_unix pam_umask pam_lastlog acct='radmin' exe='/usr/bin/login' hostname=cc-smca addr=? terminal=/dev/tty1 res=success' UID='root' AUID='radmin'",
ReceptionTime="2025-04-04 14:06:56",
SenderType="Third Party Device",
EventId="6139"

FTP_ITC.1
Auditable event Trusted channel functions
Initiation of the trusted channel

Timestamp="2025-03-18 13:37:40",
NodeId="192.0.2.2",
CompId="Management Server",
InfoMsg="TLS Connection started : Protocol = TLSv1.2  Peer = [host=192.0.2.4  port=49771]  Local = [host=192.0.2.2  port=8906]",
SenderType="Management Server",
EventId="2987302565009424590",
UserOriginator="System",
ClientIpAddress="192.0.2.4",
TypeDescription="stonegate.trusted.connection.start",
Result="Success"

Termination of the trusted channel

Timestamp="2025-03-18 13:37:40",
NodeId="192.0.2.2",
CompId="Management Server",
InfoMsg="TLS Connection ended : Protocol = TLSv1.2  Peer = [host=192.0.2.4  port=49771]  Local = [port=8906]",
SenderType="Management Server",
EventId="2987302565009424593",
UserOriginator="System",
ClientIpAddress="192.0.2.4",
TypeDescription="stonegate.trusted.connection.end",
Result="Success"

Auditable event Failure of the trusted channel functions
TLS failure

Timestamp="2025-03-17 16:57:48",
NodeId="192.0.2.2",
CompId="Management Server",
InfoMsg="TLS Connection failed : Protocol = NONE  Peer = [host=192.0.2.2  port=54902]  Local = [port=8907] ERROR: Failed to check certificate Details: Certificate Error:  The Certificate (subjectDN=CN=LogServer 192.0.2.2  serialNumber=4):  Responder's certificate not valid for signing OCSP responses",
SenderType="Management Server",
EventId="2665307750136807967",
UserOriginator="System",
ClientIpAddress="192.0.2.2",
TypeDescription="stonegate.trusted.connection.failure",
Result="Fail"

Connection failure

Timestamp="2025-02-14 09:41:55",
NodeId="192.0.2.2",
CompId="Management Server",
InfoMsg="Connection failed :  Peer = [host=192.0.2.10  port=2055] ERROR: Connection refused: /192.0.2.10:2055",
SenderType="Management Server",
EventId="274981956821713309",
UserOriginator="System",
ClientIpAddress="192.0.2.10",
TypeDescription="stonegate.connection.failure",
Result="Fail"

FTP_TRP.1/Admin
Auditable event Trusted path functions
Initiation of the trusted path

Timestamp="2025-03-17 16:56:46",
NodeId="192.0.2.2",
CompId="Management Server",
InfoMsg="TLS Connection started : Protocol = TLSv1.2  Peer = [host=192.0.2.10  port=2055]  Local = [host=192.0.2.2  port=57766]",
SenderType="Management Server",
EventId="2665307750136807942",
UserOriginator="System",
ClientIpAddress="192.0.2.10",
TypeDescription="stonegate.trusted.connection.start",
Result="Success"

Termination of the trusted path

Timestamp="2025-03-17 16:57:55",
NodeId="192.0.2.2",
CompId="Management Server",
InfoMsg="TLS Connection ended : Protocol = TLSv1.2  Peer = [host=192.0.2.10  port=2055]  Local = [host=192.0.2.2  port=57766]",
SenderType="Management Server",
EventId="2665307750136807977",
UserOriginator="System",
ClientIpAddress="192.0.2.10",
TypeDescription="stonegate.trusted.connection.end",
Result="Success"

Failure of the trusted path functions

Timestamp="2025-03-17 16:57:48",
NodeId="192.0.2.2",
CompId="Management Server",
InfoMsg="TLS Connection failed : Protocol = NONE  Peer = [host=192.0.2.2  port=54902]  Local = [port=8907] ERROR: Failed to check certificate Details: Certificate Error:  The Certificate (subjectDN=CN=LogServer 192.0.2.2  serialNumber=4):  Responder's certificate not valid for signing OCSP responses",
SenderType="Management Server",
EventId="2665307750136807967",
UserOriginator="System",
ClientIpAddress="192.0.2.2",
TypeDescription="stonegate.trusted.connection.failure",
Result="Fail"

FTP_TRP.1/Join
Auditable event Trusted path functions
SMC registration

(Initiation)

Timestamp="2025-03-17 16:40:00",
NodeId="192.0.2.2",
CompId="Management Server",
InfoMsg="TLS Connection started : Protocol = TLSv1.2  Peer = [host=192.0.2.4  port=34548]  Local = [host=192.0.2.2  port=3021]",
SenderType="Management Server",
EventId="2661634002615534055",
UserOriginator="System",
ClientIpAddress="192.0.2.4",
TypeDescription="stonegate.trusted.connection.start",
Result="Success"

SMC registration

(Termination)

Timestamp="2025-03-17 16:40:20",
NodeId="192.0.2.2",
CompId="Management Server",
InfoMsg="TLS Connection ended : Protocol = TLSv1.2  Peer = [host=192.0.2.4  port=34548]  Local = [port=3021]",
SenderType="Management Server",
EventId="2661634002615534063",
UserOriginator="System",
ClientIpAddress="192.0.2.4",
TypeDescription="stonegate.trusted.connection.end",
Result="Success"

SMC registration

(Failure)

Timestamp="2025-03-17 16:50:30",
NodeId="192.0.2.2",
CompId="Management Server",
InfoMsg="Aborting certificate polling: Certificate Request does not exist. .",
SenderType="Management Server",
EventId="2665877378764374180",
UserOriginator="System",
ClientIpAddress="192.0.2.4",
TypeDescription="stonegate.engine.initial.contact",
Result="Fail",
ObjectName="ngfw node 1"
Timestamp="2025-03-17 16:50:30",
NodeId="192.0.2.2",
CompId="Management Server",
InfoMsg="TLS Connection ended : Protocol = TLSv1.2  Peer = [host=192.0.2.4  port=59028]  Local = [port=3021]",
SenderType="Management Server",
EventId="2665877378764374181",
UserOriginator="System",
ClientIpAddress="192.0.2.4",
TypeDescription="stonegate.trusted.connection.end",
Result="Success"

Security Engine registration

(Initiation)

Timestamp="2025-03-17 16:49:01",
LogId="2002",
NodeId="192.0.2.4",
Facility="Management",
Type="Notification",
CompId="ngfw node 1",
InfoMsg="TLS: Connected connection (DNS:ManagementServer  192.0.2.2)",
ReceptionTime="2025-03-17 16:49:01",
SenderType="Firewall",
SituationId="78002",
Situation="TLS connection state",
EventId="7307442849014876114"

Security Engine registration

(Termination)

Timestamp="2025-03-17 16:49:21",
LogId="2030",
NodeId="192.0.2.4",
Facility="Management",
Type="Notification",
CompId="ngfw node 1",
InfoMsg="TLS: Connection disconnect (DNS:ManagementServer  192.0.2.2)",
ReceptionTime="2025-03-17 16:49:21",
SenderType="Firewall",
SituationId="78002",
Situation="TLS connection state",
EventId="7307442930619254766"

Security Engine registration

(Failure)

Timestamp="2025-03-17 17:22:56",
LogId="1981",
NodeId="192.0.2.4",
Facility="Management",
Type="Error",
CompId="ngfw node 1",
InfoMsg="no shared cipher",
ReceptionTime="2025-03-17 17:22:57",
SenderType="Firewall",
SituationId="9005",
Situation="FW_Communication-Communication-Error",
EventId="7307451383114893245"
Timestamp="2025-03-17 17:22:56",
LogId="1982",
NodeId="192.0.2.4",
Facility="Management",
Type="Notification",
CompId="ngfw node 1",
InfoMsg="TLS: Couldn't accept TLS connection: -3 (DNS:ManagementServer  192.0.2.2)",
ReceptionTime="2025-03-17 17:22:57",
SenderType="Firewall",
SituationId="78002",
Situation="TLS connection state",
EventId="7307451383114893246"FCO_CPC_EXT.1

FCO_CPC_EXT.1
Auditable event Enabling and disabling communication between the Security Engine and SMC.
Enabling from the Security Engine

Timestamp="2025-03-28 12:35:24",
LogId="685",
NodeId="192.0.2.4",
Facility="Management",
Type="Notification",
CompId="ngfw node 1",
InfoMsg="Connection to Management Server (192.0.2.2) enabled",
ReceptionTime="2025-03-28 12:35:42",
SenderType="Firewall",
EventId="7311365292322456237"
Timestamp="2025-03-28 12:35:40",
LogId="1028",
NodeId="192.0.2.4",
Facility="Management",
Type="Notification",
CompId="ngfw node 1",
InfoMsg="Connection to Log Server (192.0.2.2) enabled",
ReceptionTime="2025-03-28 12:35:42",
SenderType="Firewall",
EventId="7311365361041933316"

Disabling from the Security Engine Engine

Timestamp="2025-03-27 12:40:08",
LogId="2711",
NodeId="192.0.2.4",
Facility="System Utilities",
Type="Error",
Event="Notice",
CompId="ngfw node 1",
InfoMsg="Engine factory reset initiated from SMC",ReceptionTime="2025-03-27 12:40:09",
SenderType="Firewall",
SituationId="500",
Situation="FW_Notice",
EventId="7311004094162799255"
Timestamp="2025-03-27 12:40:08",
LogId="2712",
NodeId="192.0.2.4",
Facility="System Utilities",
Type="Error",
Event="Notice",
CompId="ngfw node 1",
InfoMsg="Connection to Management Server 192.0.2.2 and Log Server disabled",
ReceptionTime="2025-03-27 12:40:09",
SenderType="Firewall",
SituationId="500",
Situation="FW_Notice",
EventId="7311004094162799256"

Enabling from the SMC

Timestamp="2025-03-17 16:40:00",
NodeId="192.0.2.2",
CompId="Management Server",
InfoMsg="Initial contact from Engine Node",
SenderType="Management Server",
EventId="2661634002615534052",
UserOriginator="System",
ClientIpAddress="192.0.2.4",
TypeDescription="stonegate.engine.initial.contact",
Result="Success",
ObjectName="ngfw node 1"

Disabling from the SMC

Timestamp="2025-03-28 11:49:28",
NodeId="192.0.2.2",
CompId="Management Server",
SenderType="Management Server",
EventId="6669633148927607040",
UserOriginator="test00",
ClientIpAddress="192.0.2.1",
TypeDescription="stonegate.firewall.Reset Engine to Factory Settings",
Result="Success",
ObjectName="ngfw node 1"
Timestamp="2025-03-28 11:56:29",
NodeId="192.0.2.2",
CompId="Management Server",
SenderType="Management Server",
EventId="6669633148927607049",
UserOriginator="test00",
ClientIpAddress="192.0.2.1",
TypeDescription="stonegate.object.delete",
Result="Success",
ObjectName="ngfw"
Timestamp="2025-03-28 11:56:29",
NodeId="192.0.2.2",
CompId="Management Server",
SenderType="Management Server",
EventId="6669633148927607051",
UserOriginator="test00",
ClientIpAddress="192.0.2.1",
TypeDescription="stonegate.license.unbind",
Result="Success",
ObjectName="ngfw node 1"

FCS_IPSEC_EXT.1 IPsec Protocol
Auditable event  
Decisions to DISCARD network packets processed by the TOE

DISCARD

Timestamp="2025-04-07 14:17:13",
LogId="1472",
NodeId="192.0.2.4",
Facility="Packet Filtering",
Type="Notification",
Event="Connection discarded",
Action="Discard",
Protocol="58",
Src="::16",
Dst="FF02::16",
RuleId="46.0",
Srcif="2",
IcmpType="143",
IcmpCode="0",
CompId="ngfw node 1",
ReceptionTime="2025-04-07 14:17:34",
SenderType="Firewall",
SituationId="70019",
Situation="Connection_Discarded",
EventId="7315014794753343491",
Service="IPv6 ICMP/143/0"

Decisions to BYPASS network packets processed by the TOE

BYPASS

Timestamp="2025-04-07 14:15:53",
LogId="1390",
NodeId="192.0.2.4",
Facility="Packet Filtering",
Type="Notification",
Event="New connection",
Action="Allow",
Protocol="6",
Src="192.0.2.1",
Dst="192.0.2.4",
Sport="35476",
Dport="22",
RuleId="120.0",
Srcif="0",
CompId="ngfw node 1",
ReceptionTime="2025-04-07 14:15:54",
SenderType="Firewall",
SituationId="70018",
Situation="Connection_Allowed",
EventId="7315014459745894428",
Service="SSH"

Decisions to PROTECT network packets processed by the TOE

PROTECT

Timestamp="2025-04-07 14:21:21",
LogId="1727",
NodeId="192.0.2.4",
Facility="Packet Filtering",
Type="Notification",
Event="New connection through VPN",
Action="Allow",
Protocol="1",
Src="10.10.0.1",
Dst="203.0.113.6",
RuleId="128.0",
IcmpType="8",
IcmpCode="0",
CompId="ngfw node 1",
ReceptionTime="2025-04-07 14:21:22",
SenderType="Firewall",
SituationId="71012",
Situation="FW_New-IPsec-VPN-Connection",
EventId="7315015834135429164",
Service="Echo Request (No Code)"

IPsec SAs

Failure to establish an IPsec SA

Timestamp="2025-10-29 18:32:09",
LogId="980",
NodeId="192.0.2.4",
Facility="IPsec VPN",
Type="Error",
Src="10.0.200.10",
Dst="198.51.100.4",
Sport="500",
Dport="500",
CompId="ngfw node 1",
InfoMsg="IKEv2 SA error: Authentication failed: Remote Traffic Selector mismatch (80)  tunnel ID 1073709058",
ReceptionTime="2025-10-29 18:32:09",
SenderType="Firewall",
SituationId="12168",
Situation="IKE-Authentication-Failed",
EventId="7389368461127844820"
Timestamp="2025-10-29 18:32:09",
LogId="982",
NodeId="192.0.2.4",
Facility="IPsec VPN",
Type="Error",
Src="10.0.200.10",
Dst="198.51.100.4",
Sport="500",
Dport="500",
CompId="ngfw node 1",
InfoMsg="IPsec SA error: Authentication failed",
ReceptionTime="2025-10-29 18:32:09",
SenderType="Firewall",
SituationId="12168",
Situation="IKE-Authentication-Failed",
EventId="7389368461127844822"

IPsec SA establishment

Timestamp="2025-04-07 14:21:21",
LogId="1725",
NodeId="192.0.2.4",
Facility="IPsec VPN",
Type="Notification",
Src="10.0.200.10",
Dst="198.51.100.4",
Sport="500",
Dport="500",
CompId="ngfw node 1",
InfoMsg="IKEv2 SA responder done  Local ngfw@engine.com (email)  Remote styx@forcepoint.com (email)  Local auth method: RSA signature  Remote auth method: RSA signature  Local signature algorithm: sha256WithRSAEncryption  Remote signature algorithm: sha256WithRSAEncryption  lifetime 86400 secs cipher:aes128-cbc mac:hmac-sha256-128 prf:hmac-sha256 DH group:19",
ReceptionTime="2025-04-07 14:21:21",
SenderType="Firewall",
SituationId="12102",
Situation="IKE-SA-Responder-Done",
EventId="7315015829840463549"
Timestamp="2025-04-07 14:21:21",
LogId="1726",
NodeId="192.0.2.4",
Facility="IPsec VPN",
Type="Notification",
Src="10.10.0.0",
Dst="203.0.113.0",
CompId="ngfw node 1",
InfoMsg="IPsec SA responder done. Encryption:aes128-cbc  mac:hmac-sha2/256. Negotiation took 2 msecs.",
ReceptionTime="2025-04-07 14:21:21",
SenderType="Firewall",
SituationId="12107",
Situation="IPsec-SA-Responder-Done",
EventId="7315015829840463550"

IPsec SA termination

Timestamp="2025-04-07 14:21:27",
LogId="1728",
NodeId="192.0.2.4",
Facility="IPsec VPN",
Type="Notification",
Src="10.0.200.10",
Dst="198.51.100.4",
Sport="500",
Dport="500",
CompId="ngfw node 1",
InfoMsg="IPsec SA deleted",
ReceptionTime="2025-04-07 14:21:28",
SenderType="Firewall",
SituationId="12117",
Situation="IPsec-SA-Deleted",
EventId="7315015859905234624"
Timestamp="2025-04-07 14:21:37",
LogId="1730",
NodeId="192.0.2.4",
Facility="IPsec VPN",
Type="Notification",
Src="10.0.200.10",
Dst="198.51.100.4",
Sport="500",
Dport="500",
CompId="ngfw node 1",
InfoMsg="IKE SA deleted",
ReceptionTime="2025-04-07 14:21:37",
SenderType="Firewall",
SituationId="12116",
Situation="IKE-SA-Deleted",
EventId="7315015898559940290"

FIA_X509_EXT.1/Rev X.509 Certificate Validation (VPN)
Auditable event Unsuccessful attempt to validate a certificate
Unsuccessful attempt to validate a peer certificate

Unsuccessful attempt to validate a peer certificate: No CRL service

Timestamp="2025-03-26 15:11:33",
LogId="2193",
NodeId="192.0.2.4",
Facility="IPsec VPN",
Type="Error",
Src="10.0.200.10",
Dst="198.51.100.4",
Sport="500",
Dport="500",
CompId="ngfw node 1",
InfoMsg="Validating certificate with subject='C=FI  CN=styx-CRLfail-leaf certificate' failed because certificate with subject='C=FI  CN=styx-CRLfail-ic certificate' is not valid: Reason: (did not find trusted CA  CRL was not found  path was not verified)",
ReceptionTime="2025-03-26 15:11:33",
SenderType="Firewall",
SituationId="12168",
Situation="IKE-Authentication-Failed",
EventId="7310679811247048849"
Timestamp="2025-03-26 15:11:33",
LogId="2194",
NodeId="192.0.2.4",
Facility="IPsec VPN",
Type="Error",
Src="10.0.200.10",
Dst="198.51.100.4",
Sport="500",
Dport="500",
CompId="ngfw node 1",
InfoMsg="Certificate lookup errors: did not find trusted CA  CRL was not found  path was not verified",
ReceptionTime="2025-03-26 15:11:33",
SenderType="Firewall",
EventId="7310679811247048850"
Timestamp="2025-03-26 15:11:33",
LogId="2195",
NodeId="192.0.2.4",
Facility="IPsec VPN",
Type="Error",
Src="10.0.200.10",
Dst="198.51.100.4",
Sport="500",
Dport="500",
CompId="ngfw node 1",
InfoMsg="IKEv2 SA error: Authentication failed",
ReceptionTime="2025-03-26 15:11:33",
SenderType="Firewall",
SituationId="12168",
Situation="IKE-Authentication-Failed",
EventId="7310679811247048851"
Unsuccessful attempt to validate a peer certificate: Untrusted root CA
Timestamp="2025-03-26 15:12:39",
LogId="2254",
NodeId="192.0.2.4",
Facility="IPsec VPN",
Type="Error",
Src="10.0.200.10",
Dst="198.51.100.4",
Sport="500",
Dport="500",
CompId="ngfw node 1",
InfoMsg="Validating certificate with subject='C=FI  CN=styx-NoCA-leaf certificate' failed. Reason: (certificate was not found)",
ReceptionTime="2025-03-26 15:12:39",
SenderType="Firewall",
SituationId="12168",
Situation="IKE-Authentication-Failed",
EventId="7310680090419923150"
Timestamp="2025-03-26 15:12:39",
LogId="2255",
NodeId="192.0.2.4",
Facility="IPsec VPN",
Type="Error",
Src="10.0.200.10",
Dst="198.51.100.4",
Sport="500",
Dport="500",
CompId="ngfw node 1",
InfoMsg="Certificate lookup error: certificate was not found",
ReceptionTime="2025-03-26 15:12:39",
SenderType="Firewall",
EventId="7310680090419923151"
Timestamp="2025-03-26 15:12:39",
LogId="2256",
NodeId="192.0.2.4",
Facility="IPsec VPN",
Type="Error",
Src="10.0.200.10",
Dst="198.51.100.4",
Sport="500",
Dport="500",
CompId="ngfw node 1",
InfoMsg="IKEv2 SA error: Authentication failed",
ReceptionTime="2025-03-26 15:12:39",
SenderType="Firewall",
SituationId="12168",
Situation="IKE-Authentication-Failed",
EventId="7310680090419923152"
Unsuccessful attempt to validate a peer certificate: Certificate revoked by OCSP
Timestamp="2025-03-26 15:04:56",
LogId="1630",
NodeId="192.0.2.4",
Facility="IPsec VPN",
Type="Warning",
Src="10.0.200.10",
Dst="198.51.100.4",
Sport="500",
Dport="500",
CompId="ngfw node 1",
InfoMsg="OCSP result from http://192.0.2.8:1335 for C=FI  CN=styx-OCSP-leaf certificate: certificate is REVOKED   ",
ReceptionTime="2025-03-26 15:04:56",
SenderType="Firewall",
EventId="7310678149094704734"
Timestamp="2025-03-26 15:04:56",
LogId="1632",
NodeId="192.0.2.4",
Facility="IPsec VPN",
Type="Error",
Src="10.0.200.10",
Dst="198.51.100.4",
Sport="500",
Dport="500",
CompId="ngfw node 1",
InfoMsg="Validating certificate with subject='N/A' failed. Reason: (certificate was revoked  path was not verified)",
ReceptionTime="2025-03-26 15:04:56",
SenderType="Firewall",
SituationId="12168",
Situation="IKE-Authentication-Failed",
EventId="7310678149094704736"
Timestamp="2025-03-26 15:04:56",
LogId="1634",
NodeId="192.0.2.4",
Facility="IPsec VPN",
Type="Error",
Src="10.0.200.10",
Dst="198.51.100.4",
Sport="500",
Dport="500",
CompId="ngfw node 1",
InfoMsg="Certificate lookup errors: certificate was revoked  path was not verified",
ReceptionTime="2025-03-26 15:04:56",
SenderType="Firewall",
EventId="7310678149094704738"
Timestamp="2025-03-26 15:04:56",
LogId="1635",
NodeId="192.0.2.4",
Facility="IPsec VPN",
Type="Error",
Src="10.0.200.10",
Dst="198.51.100.4",
Sport="500",
Dport="500",
CompId="ngfw node 1",
InfoMsg="IKEv2 SA error: Authentication failed",
ReceptionTime="2025-03-26 15:04:56",
SenderType="Firewall",
SituationId="12168",
Situation="IKE-Authentication-Failed",
EventId="7310678149094704739"
Unsuccessful attempt to validate a peer certificate: Certificate revoked by CRL
Timestamp="2025-03-26 15:06:26",
LogId="1764",
NodeId="192.0.2.4",
Facility="IPsec VPN",
Type="Error",
Src="10.0.200.10",
Dst="198.51.100.4",
Sport="500",
Dport="500",
CompId="ngfw node 1",
InfoMsg="Validating certificate with subject='C=FI  CN=styx-CRL3-leaf certificate' failed. Reason: (certificate was revoked  did not find trusted CA  database method failed  path was not verified)",
ReceptionTime="2025-03-26 15:06:26",
SenderType="Firewall",
SituationId="12168",
Situation="IKE-Authentication-Failed",
EventId="7310678522756859620"
Timestamp="2025-03-26 15:06:26",
LogId="1766",
NodeId="192.0.2.4",
Facility="IPsec VPN",
Type="Error",
Src="10.0.200.10",
Dst="198.51.100.4",
Sport="500",
Dport="500",
CompId="ngfw node 1",
InfoMsg="Certificate lookup errors: certificate was revoked  path was not verified",
ReceptionTime="2025-03-26 15:06:26",
SenderType="Firewall",
EventId="7310678522756859622"
Timestamp="2025-03-26 15:06:26",
LogId="1767",
NodeId="192.0.2.4",
Facility="IPsec VPN",
Type="Error",
Src="10.0.200.10",
Dst="198.51.100.4",
Sport="500",
Dport="500",
CompId="ngfw node 1",
InfoMsg="IKEv2 SA error: Authentication failed",
ReceptionTime="2025-03-26 15:06:26",
SenderType="Firewall",
SituationId="12168",
Situation="IKE-Authentication-Failed",
EventId="7310678522756859623"
Unsuccessful attempt to validate a peer certificate: Invalid OCSP signer
Timestamp="2025-03-26 15:09:05",
LogId="1957",
NodeId="192.0.2.4",
Facility="IPsec VPN",
Type="Error",
Src="10.0.200.10",
Dst="198.51.100.4",
Sport="500",
Dport="500",
CompId="ngfw node 1",
InfoMsg="OCSP lookup failed to http://192.0.2.8:1335 for C=FI  CN=styx-OCSP3-leaf certificate: OCSP server is not authorized (possibly missing id-kp-OCSPSigning extendedKeyUsage)",
ReceptionTime="2025-03-26 15:09:05",
SenderType="Firewall",
EventId="7310679188476790693"
Timestamp="2025-03-26 15:09:05",
LogId="1960",
NodeId="192.0.2.4",
Facility="IPsec VPN",
Type="Error",
Src="10.0.200.10",
Dst="198.51.100.4",
Sport="500",
Dport="500",
CompId="ngfw node 1",
InfoMsg="Validating certificate with subject='C=FI  CN=styx-OCSP3-leaf certificate' failed. Reason: (did not find trusted CA  CRL was not found  database method failed  path was not verified  an OCSP responder in the chain did not have id-kp-OCSPSigning)",
ReceptionTime="2025-03-26 15:09:05",
SenderType="Firewall",
SituationId="12168",
Situation="IKE-Authentication-Failed",
EventId="7310679188476790696"
Timestamp="2025-03-26 15:09:05",
LogId="1963",
NodeId="192.0.2.4",
Facility="IPsec VPN",
Type="Error",
Src="10.0.200.10",
Dst="198.51.100.4",
Sport="500",
Dport="500",
CompId="ngfw node 1",
InfoMsg="IKEv2 SA error: Authentication failed",
ReceptionTime="2025-03-26 15:09:05",
SenderType="Firewall",
SituationId="12168",
Situation="IKE-Authentication-Failed",
EventId="7310679188476790699"
Any addition, replacement or removal of trust anchors in the TOE's trust store

Import of a trusted certificate authority

Timestamp="2025-03-26 15:03:02",
NodeId="192.0.2.2",
CompId="Management Server",
InfoMsg="certificate_authority element has been created.",
SenderType="Management Server",
EventId="5975793358491091417",
UserOriginator="test00",
ClientIpAddress="192.0.2.1",
TypeDescription="stonegate.object.insert",
Result="Success",
ObjectName="strongSwan CA"

Configuration of trusted certificate authorities

Timestamp="2025-03-26 14:47:00",
NodeId="192.0.2.2",
CompId="Management Server",
InfoMsg="certificate_authority_ref has been removed: <certificate_authority_ref ref='Internal RSA CA for Gateways 20250320'/>.",
SenderType="Management Server",
EventId="5973932190247944371",
UserOriginator="test00",
ClientIpAddress="192.0.2.1",
TypeDescription="stonegate.object.update.details",
Result="Success",
ObjectName="VPN profile for test VPN Certificate Authority element logs"
Timestamp="2025-03-26 14:47:08",
NodeId="192.0.2.2",
CompId="Management Server",
InfoMsg="certificate_authority_ref has been modified on its attribute: ref (CA for test VPN Certificate Authority element logs -> Internal RSA CA for Gateways 20250320).",
SenderType="Management Server",
EventId="5973932190247944376",
UserOriginator="test00",
ClientIpAddress="192.0.2.1",
TypeDescription="stonegate.object.update.details",
Result="Success",
ObjectName="VPN profile for test VPN Certificate Authority element logs"

Removal (deletion) of a trusted certificate authority

Timestamp="2025-03-26 14:47:16",
NodeId="192.0.2.2",
CompId="Management Server",
SenderType="Management Server",
EventId="5973932190247944383",
UserOriginator="test00",
ClientIpAddress="192.0.2.1",
TypeDescription="stonegate.cryptographic_key.deleted",
Result="Success",
ObjectName="CA for test VPN Certificate Authority element logs"
Timestamp="2025-03-26 14:47:16",
NodeId="192.0.2.2",
CompId="Management Server",
InfoMsg="Certificate with subject name CN=VPN Certificate Authority element logs.",
SenderType="Management Server",
EventId="5973932190247944384",
UserOriginator="test00",
ClientIpAddress="192.0.2.1",
TypeDescription="stonegate.certificate.delete",
Result="Success",
ObjectName="Certificate <CN=VPN Certificate Authority element logs> (2025-04-25)"
Timestamp="2025-03-26 14:47:16",
NodeId="192.0.2.2",
CompId="Management Server",
SenderType="Management Server",
EventId="5973932190247944382",
UserOriginator="test00",
ClientIpAddress="192.0.2.1",
TypeDescription="stonegate.object.delete",
Result="Success",
ObjectName="CA for test VPN Certificate Authority element logs"

FMT SMF.1/VPN FAU_GEN.1.1 c) All administrative actions (VPN)
Auditable event Generating / import of, changing, or deleting of cryptographic keys
Generating / import of, changing, or deleting of cryptographic keys

Creation of a VPN private key

Timestamp="2025-03-26 14:47:43",
LogId="810",
NodeId="192.0.2.4",
Facility="Management",
Type="Notification",
CompId="ngfw node 1",
InfoMsg="Private key /data/config/ipsec/priv/request202503260247442051647807924.prv has been created",
ReceptionTime="2025-03-26 14:47:45",
SenderType="Firewall",
SituationId="40010",
Situation="System_Engine-Cryptkeys-Created",
EventId="7310673815472702250"

Certificate signing request

Timestamp="2025-03-26 14:47:45",
NodeId="192.0.2.2",
CompId="Management Server",
InfoMsg="Certificate Request requested to Engine.",
SenderType="Management Server",
EventId="5973932190247944452",
UserOriginator="System",
ClientIpAddress="192.0.2.2",
TypeDescription="stonegate.vpn.certificate.request",
Result="Success",
ObjectName="ngfw;Certificate Request <CN=Audit External PKI> RSA / SHA-512"
Timestamp="2025-03-26 14:47:45",
NodeId="192.0.2.2",
CompId="Management Server",
InfoMsg="certificate_request element has been created.",
SenderType="Management Server",
EventId="5973932190247944451",
UserOriginator="System",
ClientIpAddress="192.0.2.2",
TypeDescription="stonegate.object.insert",
Result="Success",
ObjectName="Certificate Request <CN=Audit External PKI> RSA / SHA-512"

Import of a signed certificate

Timestamp="2025-03-26 14:47:53",
NodeId="192.0.2.2",
CompId="Management Server",
InfoMsg="certificate element has been created.",
SenderType="Management Server",
EventId="5973932190247944453",
UserOriginator="test00",
ClientIpAddress="192.0.2.1",
TypeDescription="stonegate.object.insert",
Result="Success",
ObjectName="Certificate <CN=Audit External PKI> RSA / SHA-256 (2025-04-25)"

Configuration of remote VPN client session timeout

Timestamp="2025-03-26 14:47:24",
NodeId="192.0.2.2",
CompId="Management Server",
InfoMsg="web_authentication has been modified on its attribute: authentication_idle_timeout (10000 -> 11111).",
SenderType="Management Server",
EventId="5973932190247944401",
UserOriginator="test00",
ClientIpAddress="192.0.2.1",
TypeDescription="stonegate.object.update.details",
Result="Success",ObjectName="ngfw"

Configuration of the cryptographic functionality

Configuration of IPSec functionality

Timestamp="2025-03-26 14:47:18",
NodeId="192.0.2.2",
CompId="Management Server",
InfoMsg="capabilities has been modified on its attribute: aes256_for_ipsec (false -> true).",
SenderType="Management Server",
EventId="5973932190247944392",
UserOriginator="test00",
ClientIpAddress="192.0.2.1",
TypeDescription="stonegate.object.update.details",
Result="Success",
ObjectName="VPN profile for test VPN profile element"
Timestamp="2025-03-26 14:47:18",
NodeId="192.0.2.2",
CompId="Management Server",
InfoMsg="capabilities has been modified on its attribute: sha2_ipsec_hash_length (256 -> 512).",
SenderType="Management Server",
EventId="5973932190247944390",
UserOriginator="test00",
ClientIpAddress="192.0.2.1",
TypeDescription="stonegate.object.update.details",
Result="Success",
ObjectName="VPN profile for test VPN profile element"
Timestamp="2025-03-26 14:47:18",
NodeId="192.0.2.2",
CompId="Management Server",
InfoMsg="capabilities has been modified on its attribute: sha2_for_ipsec (false -> true).",
SenderType="Management Server",
EventId="5973932190247944389",
UserOriginator="test00",
ClientIpAddress="192.0.2.1",
TypeDescription="stonegate.object.update.details",
Result="Success",
ObjectName="VPN profile for test VPN profile element"
Timestamp="2025-03-26 14:47:18",
NodeId="192.0.2.2",
CompId="Management Server",
InfoMsg="capabilities has been modified on its attribute: sha1_for_ipsec (true -> false).",
SenderType="Management Server",
EventId="5973932190247944391",
UserOriginator="test00",
ClientIpAddress="192.0.2.1",
TypeDescription="stonegate.object.update.details",
Result="Success",
ObjectName="VPN profile for test VPN profile element"

Configuration of the lifetime for IKEv2 SAs

Configuration of IKEv2 SA lifetimes

Timestamp="2025-03-26 14:47:18",
NodeId="192.0.2.2",
CompId="Management Server",
InfoMsg="sa_life_time has been modified (86400 -> 43200).",
SenderType="Management Server",
EventId="5973932190247944387",
UserOriginator="test00",
ClientIpAddress="192.0.2.1",
TypeDescription="stonegate.object.update.details",
Result="Success",
ObjectName="VPN profile for test VPN profile element"

Configuring IKEv2 Child SA lifetimes

Timestamp="2025-03-26 14:47:18",
NodeId="192.0.2.2",
CompId="Management Server",
InfoMsg="sa_life_time has been modified (86400 -> 43200).",
SenderType="Management Server",
EventId="5973932190247944387",
UserOriginator="test00",
ClientIpAddress="192.0.2.1",
TypeDescription="stonegate.object.update.details",
Result="Success",
ObjectName="VPN profile for test VPN profile element"

FPF_RUL_EXT.1 Packet Filtering Rules
Auditable event Application of rules configured with the log operation
Application of rules configured with the 'log' operation (VPN)

Drop traffic

Timestamp="2025-04-07 14:17:13",
LogId="1472",
NodeId="192.0.2.4",
Facility="Packet Filtering",
Type="Notification",
Event="Connection discarded",
Action="Discard",
Protocol="58",
Src="::16",
Dst="FF02::16",
RuleId="46.0",
Srcif="2",
IcmpType="143",
IcmpCode="0",
CompId="ngfw node 1",
ReceptionTime="2025-04-07 14:17:34",
SenderType="Firewall",
SituationId="70019",
Situation="Connection_Discarded",
EventId="7315014794753343491",
Service="IPv6 ICMP/143/0"

Permit traffic (BYPASS)

Timestamp="2025-04-07 14:15:53",
LogId="1390",
NodeId="192.0.2.4",
Facility="Packet Filtering",
Type="Notification",
Event="New connection",
Action="Allow",
Protocol="6",
Src="192.0.2.1",
Dst="192.0.2.4",
Sport="35476",
Dport="22",
RuleId="120.0",
Srcif="0",
CompId="ngfw node 1",
ReceptionTime="2025-04-07 14:15:54",
SenderType="Firewall",
SituationId="70018",
Situation="Connection_Allowed",
EventId="7315014459745894428",
Service="SSH"

Permit traffic (PROTECT)

Timestamp="2025-04-07 14:21:21",
LogId="1727",
NodeId="192.0.2.4",
Facility="Packet Filtering",
Type="Notification",
Event="New connection through VPN",
Action="Allow",
Protocol="1",
Src="10.10.0.1",
Dst="203.0.113.6",
RuleId="128.0",
IcmpType="8",
IcmpCode="0",
CompId="ngfw node 1",
ReceptionTime="2025-04-07 14:21:22",
SenderType="Firewall",
SituationId="71012",
Situation="FW_New-IPsec-VPN-Connection",
EventId="7315015834135429164",
Service="Echo Request (No Code)"

FTP_ITC.1/VPN Inter-TSF Trusted Channel (VPN Communications)
Auditable event Trusted channel functions
Initiation of the trusted channel

Timestamp="2025-04-07 14:21:21",
LogId="1725",
NodeId="192.0.2.4",
Facility="IPsec VPN",
Type="Notification",
Src="10.0.200.10",
Dst="198.51.100.4",
Sport="500",
Dport="500",
CompId="ngfw node 1",
InfoMsg="IKEv2 SA responder done  Local ngfw@engine.com (email)  Remote styx@forcepoint.com (email)  Local auth method: RSA signature  Remote auth method: RSA signature  Local signature algorithm: sha256WithRSAEncryption  Remote signature algorithm: sha256WithRSAEncryption  lifetime 86400 secs cipher:aes128-cbc mac:hmac-sha256-128 prf:hmac-sha256 DH group:19",
ReceptionTime="2025-04-07 14:21:21",
SenderType="Firewall",
SituationId="12102",
Situation="IKE-SA-Responder-Done",
EventId="7315015829840463549"

Termination of the trusted channel

Timestamp="2025-04-07 14:21:37",
LogId="1730",
NodeId="192.0.2.4",
Facility="IPsec VPN",
Type="Notification",
Src="10.0.200.10",
Dst="198.51.100.4",
Sport="500",
Dport="500",
CompId="ngfw node 1",
InfoMsg="IKE SA deleted",
ReceptionTime="2025-04-07 14:21:37",
SenderType="Firewall",
SituationId="12116",
Situation="IKE-SA-Deleted",
EventId="7315015898559940290"

Failure of the trusted channel functions

Timestamp="2025-10-24 21:47:09",
LogId="2448",
NodeId="192.0.2.4",
Facility="IPsec VPN",
Type="Error",
Src="10.0.200.10",
Dst="198.51.100.4",
Sport="500",
Dport="500",
CompId="ngfw node 1",
InfoMsg="No rule found for selectors ipv4(icmp:2048 203.0.113.6) ipv4(203.0.113.0-203.0.113.255) <-> ipv4(icmp:2048 10.10.0.1) ipv4(10.10.0.0-10.10.0.255)  and for IKE peers 198.51.100.4 and 10.0.200.10  and IKE IDs local ngfw@engine.com (email) and remote foobar@forcepoint.com (email): Remote ID mismatch",
ReceptionTime="2025-10-24 21:47:09",
SenderType="Firewall",
EventId="7387605596096170384"
Timestamp="2025-10-24 21:47:09",
LogId="2449",
NodeId="192.0.2.4",
Facility="IPsec VPN",
Type="Error",
Src="10.0.200.10",
Dst="198.51.100.4",
Sport="500",
Dport="500",
CompId="ngfw node 1",
InfoMsg="IKEv2 SA error: Authentication failed: Remote ID mismatch (200)  tunnel ID 1073709058",
ReceptionTime="2025-10-24 21:47:09",
SenderType="Firewall",
SituationId="12168",
Situation="IKE-Authentication-Failed",
EventId="7387605596096170385"

FTA_TSE.1.1 TOE Session Establishment
Auditable event  
Configuration of attributes used to deny establishment of remote VPN client session (location, time, day)

Configuration of attributes used to deny establishment of remote VPN client session (time, day)

Timestamp="2025-03-26 14:47:31",
NodeId="192.0.2.2",
CompId="Management Server",
InfoMsg="rule_entry (@123.0) has been added: 
<rule_entry name='discard ISAKMP and NAT-T' is_disabled='false' 
parent_rule_ref='Access rule : 
insert point' rank='-25.0' rule_tag_major_id='123' 
tag='123.0'><match_part><match_sources><match_source_ref type='network_element' 
value='ANY'/></match_sources><match_destinations><match_destination_ref 
type='network_element' 
value='$$ Local Cluster'/></match_destinations><match_services><match_service_ref 
type='application' 
value='ISAKMP'/><match_service_ref type='application' 
value='NAT-T'/></match_services><rule_validity_times><rule_validity_time_ref 
type='rule_validity_time' 
value='Weekends'/></rule_validity_times></match_part><option><log_policy closing_mode='true' 
log_level='undefined' mss_enforce='false'><payload_modes><payload_mode 
type='string' value='nothing'/></payload_modes></log_policy></option></rule_entry>.",
SenderType="Management Server",
EventId="5973932190247944426",
UserOriginator="test00",
ClientIpAddress="192.0.2.1",
TypeDescription="stonegate.object.update.details",
Result="Success",
ObjectName="auditpolicy"
Configuration of attributes used to deny establishment of remote VPN client session (location, time, day) (Continued)

Timestamp="2025-03-26 14:47:28",
NodeId="192.0.2.2",
CompId="Management Server",
InfoMsg="rule_validity_time element has been created.",
SenderType="Management Server",
EventId="5973932190247944417",
UserOriginator="test00",
ClientIpAddress="192.0.2.1",
TypeDescription="stonegate.object.insert",
Result="Success",
ObjectName="Weekends"

Configuration of attributes used to deny establishment of remote VPN client session (location, time, day) (Continued)

Timestamp="2025-03-26 14:47:40",
NodeId="192.0.2.2",
CompId="Management Server",
InfoMsg="week_day has been modified (mo tu we th fr sa su -> mo tu we th fr).",
SenderType="Management Server",
EventId="5973932190247944437",
UserOriginator="test00",
ClientIpAddress="192.0.2.1",
TypeDescription="stonegate.object.update.details",
Result="Success",
ObjectName="Weekends"

Configuration of attributes used to deny establishment of remote VPN client session (location, time, day) (Continued)

Timestamp="2025-03-26 14:47:40",
NodeId="192.0.2.2",
CompId="Management Server",
InfoMsg="rule_time_repeat_end has been modified (07:00 -> 06:00).",
SenderType="Management Server",
EventId="5973932190247944438",
UserOriginator="test00",
ClientIpAddress="192.0.2.1",
TypeDescription="stonegate.object.update.details",
Result="Success",
ObjectName="Weekends"

Configuration of attributes used to deny establishment of remote VPN client session (location, time, day) (Continued)

Timestamp="2025-03-26 14:47:40",
NodeId="192.0.2.2",
RuleId="124.1",
CompId="Management Server",
InfoMsg="IPv4 Access @124.1 has been modified.",
SenderType="Management Server",
EventId="5973932190247944441",
UserOriginator="test00",
ClientIpAddress="192.0.2.1",
TypeDescription="stonegate.object.update",
Result="Success",
ObjectName="auditpolicy"

Configuration of attributes used to deny establishment of remote VPN client session (location, time, day) (Continued)

Timestamp="2025-03-26 14:47:40",
NodeId="192.0.2.2",
CompId="Management Server",
InfoMsg="rule_validity_times has been added: <rule_validity_times><rule_validity_time_ref type='rule_validity_time' value='Weekends'/></rule_validity_times>.",
SenderType="Management Server",
EventId="5973932190247944442",
UserOriginator="test00",
ClientIpAddress="192.0.2.1",
TypeDescription="stonegate.object.update.details",
Result="Success",
ObjectName="auditpolicy"

Configuration of attributes used to deny establishment of remote VPN client session (location, time, day) (Continued)

Timestamp="2025-03-26 14:47:40",
NodeId="192.0.2.2",
CompId="Management Server",
SenderType="Management Server",
EventId="5973932190247944443",
UserOriginator="test00",
ClientIpAddress="192.0.2.1",
TypeDescription="stonegate.object.update",
Result="Success",
ObjectName="auditpolicy"

FAU_GEN.1/VPN Audit Data Generation (VPN Gateway)
Auditable event  
Indication that TSF self-test was completed (NGFW)

Timestamp="2025-03-27 16:44:32",
LogId="1107",
NodeId="192.0.2.4",
Facility="System Utilities",
Type="Notification",
CompId="ngfw node 1",
InfoMsg="Thu Mar 27 16:43:48 UTC 2025 SHA512withECDSA checksum of the root file system succeed",
ReceptionTime="2025-03-27 16:44:33",
SenderType="Firewall",
SituationId="73200",
Situation="Self_Test-Success",
EventId="7311065602389443667"
Timestamp="2025-03-27 16:44:32",
LogId="1102",NodeId="192.0.2.4",
Facility="System Utilities",
Type="Notification",
CompId="ngfw node 1",
InfoMsg="Thu Mar 27 16:43:31 UTC 2025 Cryptographic self-tests succeeded",
ReceptionTime="2025-03-27 16:44:33",
SenderType="Firewall",
SituationId="73202",
Situation="Self_Test-Cryptography-Success",
EventId="7311065602389443662"
Timestamp="2025-03-27 16:44:32",
LogId="1120",
NodeId="192.0.2.4",
Facility="Management",
Type="Notification",
CompId="ngfw node 1",
InfoMsg="Thu Mar 27 16:43:48 2025 Integrity check: Engine image signature verified",
ReceptionTime="2025-03-27 16:44:33",
SenderType="Firewall",
SituationId="73200",
Situation="Self_Test-Success",
EventId="7311065602389443680"

Indication that TSF self-test was completed (SMC)

Timestamp="2025-03-26 14:46:50",
NodeId="::1",
Type="Notification",
CompId="3",
InfoMsg="Mar 26 14:46:50 smca-mn-xray sudo: test00 : PWD=/home/test00 ; USER=root ; COMMAND=/bin/grep 'smca-mn-xray root: fipscheck:Performing FIPS integrity check\\.\\.\\.$' /var/log/smca/smca.log",
ReceptionTime="2025-03-26 14:46:50",
SenderType="Third Party Device",
EventId="3371"

Failure of self-test (NGFW)

Timestamp="2025-04-07 14:17:47",
LogId="1",
NodeId="192.0.2.4",
Facility="System Utilities",
Type="System alert",
CompId="ngfw node 1",
InfoMsg="Mon Apr  7 14:16:01 UTC 2025 SHA512withECDSA checksum of the root file system failed",
ReceptionTime="2025-04-07 14:17:48",
SenderType="Firewall",
SituationId="73201",
Situation="Self_Test-Fail",
AlertSeverity="Critical",
EventId="7315014936755699713"
Timestamp="2025-04-07 14:17:47",
LogId="1571",
NodeId="192.0.2.4",
Facility="System Utilities",
Type="System alert",
CompId="ngfw node 1",
InfoMsg="Mon Apr  7 14:16:01 UTC 2025 FIPS: rootfs integrity check FAILED  rebooting...",
ReceptionTime="2025-04-07 14:27:05",
SenderType="Firewall",
SituationId="73201",
Situation="Self_Test-Fail",
EventId="7315014936487265827"

Failure of self-test (SMC)
Timestamp="2025-04-07 14:26:59",
NodeId="::1",
Type="Notification",
CompId="3",
InfoMsg="Apr 7 14:26:02 smca-mn-xray root: Fatal FIPS Error: fipscheck:ERROR:FIPS integrity check failed. /usr/bin/smca-fipscheck: 255",
ReceptionTime="2025-04-07 14:26:59",
SenderType="Third Party Device",
EventId="2340"