×

Warning message

  • Cisco Support Forums is in Read Only mode while the site is being migrated.
  • Cisco Support Forums is in Read Only mode while the site is being migrated.

Remote VPN Access Login Event Email Notification

Unanswered Question
Jun 13th, 2014
User Badges:

Hi,

 

I have a cisco pix 525 with IOS 8 on it.

It is configured for remote access. I want to get email notifications when someone successfully logs into the VPN. I have looked and it doesn't really seem to be a decipherable way to do this.

 

Any help would be appreciated, a break down of what is required or even what commands need to be run to accomplish this.

As a side note, the port of the remote server for smtp is 587 as Comcast, one of the worst companies that exists, is blocking 25 and 26.

 

Jeff

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
Marvin Rhoads Fri, 06/13/2014 - 16:44
User Badges:
  • Super Silver, 17500 points or more
  • Hall of Fame,
  • Cisco Designated VIP,

    2017 Firewalling, Network Management, VPN

Your Pix with ASA software 8.0 supports sending syslog messages to an e-mail destination.

You would choose the syslog message number(s) that is (or are) generated by user authentication ( I think it's 113004 if you're using a AAA server and 113012 for locally authenticated users - reference) and define it (them) in a message list.

Then setup your syslog to send events matching that message list to your desired e-mail destination.

Here's a link to the relevant section of the configuration guide.

jeff slansky Fri, 06/13/2014 - 22:04
User Badges:

hi,

i looked into this a little bit. i have done the following:

logging enable
logging timestamp
logging host inside 10.1.1.1
logging list THCLogList level debugging class vpn
logging trap THCLogList
logging mail debugging THCLogList
logging recipient-address xxx@yyyy.com

logging from-address xxx@yyyy.com
smtp-server xxx.xxx.xxx.xxx

 

my questions would be:

1. can the pix serve as the sys log server? its just a unix box right? my thought is yes and the ip that is there is of the inside port of the pix.

2. no where in the documentation do i see where you can set a custom smtp port. what am i missing?

3. i don't see any where the documentation to specify the password to authenticate with, or any of the other settings, like SSL etc.

4. the smtp server is at an external location, so its not on the same network. its hosted in a data center in texas

thanks

jeff

Marvin Rhoads Sat, 06/14/2014 - 07:53
User Badges:
  • Super Silver, 17500 points or more
  • Hall of Fame,
  • Cisco Designated VIP,

    2017 Firewalling, Network Management, VPN

When we log to the firewall itself, that's a logging buffer (limited size) and not a logging host.

E-mailing log events is a very basic function and not used very often in my experience. It does not support authentication or changing the default port. As long it is an address reachable via the default smtp port, it can be used.

Even the more full featured Smart call home (SCH) support varies by platform. As of right now, only data center products (Nexus and MDS) have built-in the ability to modify the default smtp port to something other than 25. E-mail SCH is unauthenticated only.

I missed what you were saying in your original post about the e-mail server tcp port. In that case, you'll likely have to proxy via an external host. You could probably hack together a simple mail relay (or syslog to mail handler) working on a Raspberry Pi or similar tiny Linux device.

jeff slansky Mon, 06/16/2014 - 12:25
User Badges:
Hi, Thanks for your help. I didn't think that it did support it. To go around the problem i setup a the SMTP service on my wins server. i have two futher questions: 1: i validated that your numbers on the syslog id's are correct. is there an associated disconnect message? i looked through the rest of the messages in that class and i think that it is 113019. is that correct? 2: what is the actual syntax that is required to get just those events? thanks again, jeff
Marvin Rhoads Mon, 06/16/2014 - 13:24
User Badges:
  • Super Silver, 17500 points or more
  • Hall of Fame,
  • Cisco Designated VIP,

    2017 Firewalling, Network Management, VPN

You're welcome.

I do believe 113019 is the disconnect message. That's what I see on one of my ASAs. I am not seeing the 113012 for login but do see a 750006 message. (SA up) You should watch yours and validate the message IDs. (You may need to crank up the logging level to 6 temporarily to make sure you capture the relevant ones.)

So using the IDs I see you would use the following syntax in your config:

logging list VPN-Event-List_1 message 113012logging list VPN-Event-List_2 message 750006logging list VPN-Event-List level Informationalsmtp-server &lt;your server address&gt;<br />logging from-address &lt;from field you want the ASA to show as&gt;<br />logging recipient-address &lt;destination email&gt; level Informational<br />logging mail VPN-Event-List_1

logging mail VPN-Event-List_2

Please rate helpful replies and mark when answered. Thanks.

jeff slansky Mon, 06/16/2014 - 12:13
User Badges:
Hi, Thanks for your help. I didn't think that it did support it. To go around the problem i setup a the SMTP service on my wins server. i have two futher questions: 1: i validated that your numbers on the syslog id's are correct. is there an associated disconnect message? i looked through the rest of the messages in that class and i dont see anything. 2: what is the actual syntax that is required to get just those events?

Actions

This Discussion