<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic FTD RA VPN Logs in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ftd-ra-vpn-logs/m-p/5059020#M1110769</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I try to find some Information of Remote Access or Mail ingress/egress activities on an FTD 3110 Tech support file or the Device it self.&lt;/P&gt;
&lt;P&gt;I don't have any access to the FMC.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 07 Apr 2024 08:57:31 GMT</pubDate>
    <dc:creator>alex.f.</dc:creator>
    <dc:date>2024-04-07T08:57:31Z</dc:date>
    <item>
      <title>FTD RA VPN Logs</title>
      <link>https://community.cisco.com/t5/network-security/ftd-ra-vpn-logs/m-p/5059020#M1110769</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I try to find some Information of Remote Access or Mail ingress/egress activities on an FTD 3110 Tech support file or the Device it self.&lt;/P&gt;
&lt;P&gt;I don't have any access to the FMC.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 07 Apr 2024 08:57:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-ra-vpn-logs/m-p/5059020#M1110769</guid>
      <dc:creator>alex.f.</dc:creator>
      <dc:date>2024-04-07T08:57:31Z</dc:date>
    </item>
    <item>
      <title>Re: FTD RA VPN Logs</title>
      <link>https://community.cisco.com/t5/network-security/ftd-ra-vpn-logs/m-p/5059721#M1110860</link>
      <description>&lt;P&gt;you want FTD always debug the connect from Anyconnect ?&lt;BR /&gt;MHM&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2024 07:31:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-ra-vpn-logs/m-p/5059721#M1110860</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-04-08T07:31:10Z</dc:date>
    </item>
    <item>
      <title>Re: FTD RA VPN Logs</title>
      <link>https://community.cisco.com/t5/network-security/ftd-ra-vpn-logs/m-p/5060443#M1110865</link>
      <description>&lt;P&gt;hi,&lt;BR /&gt;my question is whether there is a possibility to extract connection information from the TechSupport file of an FTD afterwards, which provides information about malicious network activities to a device in the local network.&lt;/P&gt;
&lt;P&gt;For example, I am looking for successful RA VPN dial-ins by users or access to certain ports.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2024 12:45:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-ra-vpn-logs/m-p/5060443#M1110865</guid>
      <dc:creator>alex.f.</dc:creator>
      <dc:date>2024-04-08T12:45:34Z</dc:date>
    </item>
    <item>
      <title>Re: FTD RA VPN Logs</title>
      <link>https://community.cisco.com/t5/network-security/ftd-ra-vpn-logs/m-p/5060471#M1110867</link>
      <description>&lt;P&gt;Most historical logs (including the type you are asking about) are streamed to the managing FMC in near real time and then deleted on the local device.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2024 12:55:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-ra-vpn-logs/m-p/5060471#M1110867</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2024-04-08T12:55:12Z</dc:date>
    </item>
    <item>
      <title>Re: FTD RA VPN Logs</title>
      <link>https://community.cisco.com/t5/network-security/ftd-ra-vpn-logs/m-p/5062958#M1110932</link>
      <description>&lt;P&gt;Thanks for the feedback, unfortunately I already suspected this.&lt;/P&gt;
&lt;P&gt;We are currently trying to restore the FMC data. &lt;BR /&gt;But this may take a few more weeks.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2024 13:11:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-ra-vpn-logs/m-p/5062958#M1110932</guid>
      <dc:creator>alex.f.</dc:creator>
      <dc:date>2024-04-09T13:11:02Z</dc:date>
    </item>
    <item>
      <title>Re: FTD RA VPN Logs</title>
      <link>https://community.cisco.com/t5/network-security/ftd-ra-vpn-logs/m-p/5063029#M1110933</link>
      <description>&lt;P&gt;Did you check&lt;/P&gt;
&lt;P&gt;Show vpn sessiondb anyconnect detail&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This can access from cli of ftd' it give you breif which user connect to your FTD know&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2024 13:27:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-ra-vpn-logs/m-p/5063029#M1110933</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-04-09T13:27:47Z</dc:date>
    </item>
    <item>
      <title>Re: FTD RA VPN Logs</title>
      <link>https://community.cisco.com/t5/network-security/ftd-ra-vpn-logs/m-p/5063219#M1110936</link>
      <description>&lt;P&gt;The command "Show vpn sessiondb anyconnect detail" will only show current connections with details (such as username, user IP real address, assigned VPN address, connection profile, tunnel-group, duration etc.).&lt;/P&gt;
&lt;P&gt;It will not show details of any previous sessions.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2024 15:06:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-ra-vpn-logs/m-p/5063219#M1110936</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2024-04-09T15:06:33Z</dc:date>
    </item>
    <item>
      <title>Re: FTD RA VPN Logs</title>
      <link>https://community.cisco.com/t5/network-security/ftd-ra-vpn-logs/m-p/5065755#M1110963</link>
      <description>&lt;P&gt;Thanks, but even FMC don't keep this info for long time (without external syslog).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If user access via ssl vpn to ftd and it idle timeout is not end he can see it details via show vpn sessiondb.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Thu, 11 Apr 2024 06:20:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-ra-vpn-logs/m-p/5065755#M1110963</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-04-11T06:20:48Z</dc:date>
    </item>
  </channel>
</rss>

