01-29-2007 06:45 AM - edited 02-21-2020 01:23 AM
I would like to keep a simple log of who
VPNs into the my 3005.
Does anyone have a solution to do this?
01-30-2007 11:38 AM
Are the userd local or are you using RADIUS/TACACs?
01-30-2007 12:19 PM
Right now it is set to NT domain.
I guess I could use IAS on Windows server.
I'm looking into maybe sysloging everything and then see if Kiwi syslog can filter it?
scott
01-30-2007 12:24 PM
You could use your event logs, which stinks. IAS would be better. Let me see what the syslog looks like and we'll see if Kiwi can filter or if we have to write a script.
01-30-2007 12:49 PM
The syslog is pretty good. Here's an example:
2007-01-30 14:45:19 Local7.Notice 172.16.255.254 63161228 01/30/2007 14:45:33.000 SEV=4 AUTH/22 RPT=41714 70.226.xx.xx User [DOMAIN\my_id] Group [vpn-group] connected, Session Type: IPSec
You can filter on "connected" in Kiwi. Note that you will also get disconnect notices with that filter. If you really just want connections, filter on something longer like "[vpn-group] connected"
HTH and please rate.
Here's a disconnect for reference:
2007-01-30 14:45:24 Local7.Notice 172.16.255.254 63161427 01/30/2007 14:45:38.460 SEV=4 AUTH/28 RPT=40305 70.226.xx.xx User [DOMAIN\my_id] Group [vpn-group] disconnected: Session Type: IPSec/NAT-T Duration: 0:00:05 Bytes xmt: 56 Bytes rcv: 0 Reason: User Requested
02-04-2007 12:09 PM
Thanks, that worked.
Having Kiwi put it into a differnet txt file, then going to clean it up with excel.
thanks..
SCott
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: