Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations gkittelson on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Remote Access Vpn logging on a Pix 515e 1

Status
Not open for further replies.

said07

IS-IT--Management
May 3, 2004
168
US
I provide remote access vpn through a pix 515e.
I have a syslog server working on the network and the pix configured to send the traps to it.
What do I need to tell the pix to send info about the vpn ins and outs to the sys log server?

Thanks
 
I have a remote user who tells me that he gets kiked out and reconnects couple of times a day lately. I need to see that on the logs. Successful logins and logouts.
 
what are you logging now? try logging trap informational how many other remote users do you have? is this the only user?
 
Right now I am logging Warnings and yes he is the only one complaining.
I guess he might have internet connection problems as no other has complained.
 
i agree...if you change your logging to

logging trap informational

you will get the desired information
 
logging trap debugging, for the purposes of this problem...

/

tim@tim-laptop ~ $ sudo apt-get install windows
Reading package lists... Done
Building dependency tree
Reading state information... Done
E: Couldn't find package windows...Thank Goodness!
 
Thanks to everyone.
I was able to find a nice piece of software that parses the logs and show me the vpn activity without difficulty.
I don't want to give a name so I don't sound like I am selling the product but if anyone is interested please let me know and I will reply with the software name.
I was also truly impressed with the support they provided me even though I was just evaluating.
 
Said07, would you please send me the company that you found for logging vpn activity? I am in the same boat and need a good solution for compliance measure. Please send to ddutton44@gmail.com.

thanks
 
You can do it yourself on the PIX.

What you do is this:
"logging list datanet-list message 106015-106023
...etc...
logging buffered datanet-list
logging enable


That way you don't create a massive log you need to parse for the bits you want - you create a small log with just the messages you wanted to see.
 
Hi Said07,

Can you tell me the VPN logging softrware to control VPN user?

Thanks.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top