Group Information and Session Type values are not populated in the syslogs. I would like to know why those informations are not populated in the syslog. Am I missed any configuration?
<189>1411153: 2009 Sep 16 00:06:51.940 EST -5:00 %AUTH-5-28: RPT=10309: 18.104.22.168: User [foobar] Group [Base Group] disconnected: Session Type: IPSec Duration: 12:22:22 Bytes xmt: 94835896 Bytes rcv: 10344280 Reason: User Requested
<189>57: 2009 Nov 02 02:55:55.160 PST -8:00 %AUTH-5-28: RPT=1: 22.214.171.124: User [saran] disconnected: Duration: 0:02:00 Bytes xmt: 2208 Bytes rcv: 0 Reason: User Requested
Please find the difference between the above two logs for a VPN User disconnection and guide me to get the log information like the Old log.
Any Configuration needs to check?
My Syslog Configuration in VPN 3000 Concentrator:
I followed the below steps to configure my Cisco 3000 VPN Concentrator:
- Configuring Syslog Server
- Login to the Cisco VPN 3000 Concentrator Management console.
- Goto Configuration > System> Events >Syslog Servers
- Click the Add button
- In the Syslog Server text box enter the IP Address of the machine where Firewall Analyzer is running.
- Enter the Port value. The default syslog server port for Firewall Analyzer is 514.
- Facility is Local 7
- Configuring Syslog Events
- Goto Configuration > System> Events >General
- For Syslog Format you can either select Original or Cisco IOS Compatible format.
- For Events to Syslog select Severities 1-5
- All other configurations are default for this page.
- Click Apply button
Awaiting your feedback.
Thanks & Regards,