<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA VPN logging in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-vpn-logging/m-p/3532695#M493017</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We’re currently (and have been) able to log VPN access through our firewall for our IPSEC clients via RADIUS in MS InternetAuthentication Service (IAS) on our domain controller.&amp;nbsp; However, moving forward with LDAP authentication, we need a replacement for this functionality.&amp;nbsp; We need to log account, IP address, start and stop times.&amp;nbsp; I’ve done a quick Internet search of ASA Logging (VPN) without success.&amp;nbsp; I’ve also tried to find a place to configure this in ASDM on theASA without success.&amp;nbsp; Is this possible without 3&lt;SUP&gt;rd&lt;/SUP&gt; partysoftware via ASDM?&amp;nbsp; If not, what scripting 3&lt;SUP&gt;rd&lt;/SUP&gt; party tools would you recommend?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 16 Nov 2011 16:23:13 GMT</pubDate>
    <dc:creator>kardos420</dc:creator>
    <dc:date>2011-11-16T16:23:13Z</dc:date>
    <item>
      <title>ASA VPN logging</title>
      <link>https://community.cisco.com/t5/network-security/asa-vpn-logging/m-p/3532695#M493017</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We’re currently (and have been) able to log VPN access through our firewall for our IPSEC clients via RADIUS in MS InternetAuthentication Service (IAS) on our domain controller.&amp;nbsp; However, moving forward with LDAP authentication, we need a replacement for this functionality.&amp;nbsp; We need to log account, IP address, start and stop times.&amp;nbsp; I’ve done a quick Internet search of ASA Logging (VPN) without success.&amp;nbsp; I’ve also tried to find a place to configure this in ASDM on theASA without success.&amp;nbsp; Is this possible without 3&lt;SUP&gt;rd&lt;/SUP&gt; partysoftware via ASDM?&amp;nbsp; If not, what scripting 3&lt;SUP&gt;rd&lt;/SUP&gt; party tools would you recommend?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Nov 2011 16:23:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-vpn-logging/m-p/3532695#M493017</guid>
      <dc:creator>kardos420</dc:creator>
      <dc:date>2011-11-16T16:23:13Z</dc:date>
    </item>
    <item>
      <title>Re: ASA VPN logging</title>
      <link>https://community.cisco.com/t5/network-security/asa-vpn-logging/m-p/3532696#M493019</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are two vehicles available for logging user sessions.&amp;nbsp; The method that makes most sense is to continue to use RADIUS accounting. This can be used even if the authentication method is no longer RADIUS.&amp;nbsp; The other option is to leverage syslog for this purpose, but that is a lot less desirable as normal commercial products will not parse these syslog messages in to a useful format for running reports.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Nov 2011 23:04:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-vpn-logging/m-p/3532696#M493019</guid>
      <dc:creator>stsong</dc:creator>
      <dc:date>2011-11-17T23:04:00Z</dc:date>
    </item>
    <item>
      <title>Re: ASA VPN logging</title>
      <link>https://community.cisco.com/t5/network-security/asa-vpn-logging/m-p/3532697#M493020</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Syslog-ng can be used for capturing syslog and you can use scripts to pull information out of general logs into a usable format, requires some basic linux scripting ability.&amp;nbsp; Solarwinds Kiwi Syslog is a windows based tool that has some basic filtering that is more of a point and click gui.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-d&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Apr 2012 16:26:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-vpn-logging/m-p/3532697#M493020</guid>
      <dc:creator>doedelmo</dc:creator>
      <dc:date>2012-04-27T16:26:31Z</dc:date>
    </item>
    <item>
      <title>Re: ASA VPN logging</title>
      <link>https://community.cisco.com/t5/network-security/asa-vpn-logging/m-p/3532698#M493022</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You could also deploy CD-Agent (AD_Agent) and configure your ASA for Identity Firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This would allow mapping of user to IP, and you could then correallte Radius Start_Stop, with the Identity FW Logs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For information just google "ASA Identity Firewall with AD Agent"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Aug 2013 19:29:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-vpn-logging/m-p/3532698#M493022</guid>
      <dc:creator>leciscokid</dc:creator>
      <dc:date>2013-08-19T19:29:15Z</dc:date>
    </item>
  </channel>
</rss>

