Explains how monitoring XR shell captures, associates, and protects audit records of shell commands for enhanced security and compliance.
Monitor XR shell commands is an IOS XR security capability that
-
audits run and bash sessions on the active Route Processor (RP) but excludes shell built-in commands
-
associates each command with the original authenticated user, and
-
sends execution events to a logging mechanism called the shell-logger.
The Shell-Logger uses Tetragon to provide command accountability for monitored IOS XR run and bash sessions on the active Route Processor (RP). It creates protected audit records that associate shell activity with authenticated IOS XR users, supporting security monitoring, compliance, and troubleshooting. Run and bash sessions on the standby RP or other nodes are not monitored.
Tetragon runtime observability
Tetragon, an extended Berkeley Packet Filter (eBPF)-based runtime observability engine, uses eBPF programs to track kernel-level process execution events. Each tracked process execution—including shell commands, script-based commands, and commands executed in nested shells—generates an event. Each event records the timestamp, username, executed command, and whether the command originated from an IOS XR run or bash session.
|
Feature Name |
Release Information |
Feature Description |
|---|---|---|
|
Monitor XR shell commands |
Release 26.3.1 |
Introduced in this release on: Fixed Systems (8200 [ASIC: Q100, Q200, P100], 8700 [ASIC: P100, K100], 8010 [ASIC: A100]); Centralized Systems (8600 [ASIC: Q200]); Modular Systems (8800 [LC ASIC: Q100, Q200, P100]) You can now trace run and bash commands to specific users and identify potential system compromises. By implementing shell-level user activity tracking, the router records each action, the user who performed it, and its timestamp. You can use this data to monitor user behavior, detect potentially malicious activity, and respond rapidly to security incidents. This feature introduces these changes: CLI: |