cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
331
Views
0
Helpful
2
Replies

Historical logging of VPN sessions

gginty
Level 1
Level 1

We are running ASA 7.2(2) and ASDM 5.2. Realtime logging of VPN clients through the ASA box is turned on. We need a way to be able to log and view previous days VPN logging's, failed attempts etc. How does one go about this?

2 Replies 2

jj27
Spotlight
Spotlight

Install a Syslog server and configure the ASA to report to it.

A good one I've found is ManageEngines Firewall Analyzer. You can run many reports, one of them including who was on the VPN, for how long, and when.

http://www.manageengine.com/products/firewall/

Thanks. I ended up getting a trial solarwinds syslog server. We are only interested in the VPN login sessions and have set trap level to 6. However the ASA appears to be sending everything over and it is difficult to track. I have notice as well that from the ASDM viewer I can see the actual name of the user who is logged in. Is it possible to set ASA up to just report the VPN login/logout of the user name to the syslog server?

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: