cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
462
Views
0
Helpful
1
Replies

PAM user error on ids 4235 Version 4.1(5)S190

garyprice
Level 1
Level 1

this is error message

Sep 9 14:34:30Sep 9 14:34:31 Defiant pam_tally[1321]: pam_tally: pam_get_uid; no such user "sensor name"

it is occuring every minute.

any ideas?

1 Reply 1

a.arndt
Level 3
Level 3

I can only hazard a guess. It looks like something is trying to login in to your sensor, and it is most likely automated.

Is it possible that some kind of network management system is probing your system? Do you have TELNET enabled? WhatsUp from Ipswitch is known to tickle telnet servers with a generic account, I believe, in order to determine the status of the server (up or down)…

Another possibility is that you have a RDEP / SDEE client with a misconfigured username (read: typo) trying to access alarms on the sensor.

Have you sniffed your Command and Control interface to see what the offending packets look like?

Alex Arndt

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card