<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN Connection Log Activity in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/vpn-connection-log-activity/m-p/1698746#M534747</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Dipak,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Enable the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE&gt;logging class vpn buffered debugging //to log to the buffer&lt;BR /&gt;&lt;PRE&gt;logging class vpn trap debugging //to log to a syslog server&lt;BR /&gt;&lt;PRE&gt;logging class vpnc buffered debugging //logging for vpn client activities&lt;BR /&gt;&lt;/PRE&gt;
&lt;BR /&gt;&lt;BR /&gt;Hope this helps!&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Anu&lt;BR /&gt;&lt;BR /&gt;P.S. Please mark this question as resolved if it has been answered. Do rate &lt;BR /&gt;helpful posts.&lt;BR /&gt;&lt;/PRE&gt;
&lt;BR /&gt;&lt;BR /&gt;&lt;/PRE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 28 Jul 2011 16:45:34 GMT</pubDate>
    <dc:creator>Anu M Chacko</dc:creator>
    <dc:date>2011-07-28T16:45:34Z</dc:date>
    <item>
      <title>VPN Connection Log Activity</title>
      <link>https://community.cisco.com/t5/network-security/vpn-connection-log-activity/m-p/1698745#M534746</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have configured client to site vpn at one of our client site and it's running properly, but we are unable to monitor the vpn connection log. We have configured syslog server for the same. The user are authenticating from the local database of ASA. We have configured the following thing at ASA for VPN connection logging:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ASA# &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;logging enable&lt;/P&gt;&lt;P&gt;logging timestamp&lt;/P&gt;&lt;P&gt;logging standby&lt;/P&gt;&lt;P&gt;logging console informational&lt;/P&gt;&lt;P&gt;logging monitor informational&lt;/P&gt;&lt;P&gt;logging trap informational&lt;/P&gt;&lt;P&gt;logging history informational&lt;/P&gt;&lt;P&gt;logging asdm informational&lt;/P&gt;&lt;P&gt;logging facility 23&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;logging host INSIDE 172.21.15.10(Syslog server IP)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The asdm and syslog server are not capturing the log of VPN Connectin. The client want the following log information of VPN Connection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. VPN login and exit time.&lt;/P&gt;&lt;P&gt;2. VPN login username and password&lt;/P&gt;&lt;P&gt;3. If possible, what they have done after logging.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please help me to solve this issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot for your support.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Dipak&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 21:05:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-connection-log-activity/m-p/1698745#M534746</guid>
      <dc:creator>dipak jaiswal</dc:creator>
      <dc:date>2019-03-11T21:05:08Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Connection Log Activity</title>
      <link>https://community.cisco.com/t5/network-security/vpn-connection-log-activity/m-p/1698746#M534747</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Dipak,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Enable the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE&gt;logging class vpn buffered debugging //to log to the buffer&lt;BR /&gt;&lt;PRE&gt;logging class vpn trap debugging //to log to a syslog server&lt;BR /&gt;&lt;PRE&gt;logging class vpnc buffered debugging //logging for vpn client activities&lt;BR /&gt;&lt;/PRE&gt;
&lt;BR /&gt;&lt;BR /&gt;Hope this helps!&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Anu&lt;BR /&gt;&lt;BR /&gt;P.S. Please mark this question as resolved if it has been answered. Do rate &lt;BR /&gt;helpful posts.&lt;BR /&gt;&lt;/PRE&gt;
&lt;BR /&gt;&lt;BR /&gt;&lt;/PRE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Jul 2011 16:45:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-connection-log-activity/m-p/1698746#M534747</guid>
      <dc:creator>Anu M Chacko</dc:creator>
      <dc:date>2011-07-28T16:45:34Z</dc:date>
    </item>
    <item>
      <title>VPN Connection Log Activity</title>
      <link>https://community.cisco.com/t5/network-security/vpn-connection-log-activity/m-p/1698747#M534748</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot for your support. It's working now. I have some query which are mentioned below :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. It's showing only the login time, but not the logout time.&lt;/P&gt;&lt;P&gt;2. If client is doing any activities, it's not showing at syslog server.&lt;/P&gt;&lt;P&gt;3. Suppose a client connect or logout via vpn, at the same time mail will be generated by ASA&amp;nbsp; to the concerned mail id that from this ip with user id and time mentioned in the maid id, has logged in or logged out. Is it possibe ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Dipak&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Jul 2011 08:28:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-connection-log-activity/m-p/1698747#M534748</guid>
      <dc:creator>dipak jaiswal</dc:creator>
      <dc:date>2011-07-29T08:28:05Z</dc:date>
    </item>
    <item>
      <title>VPN Connection Log Activity</title>
      <link>https://community.cisco.com/t5/network-security/vpn-connection-log-activity/m-p/1698748#M534749</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try if this helps.. When you enable 'logging buffered debugging'&amp;nbsp; - you can see all the logs with message ID#. Select the messages you want to get emails for and add the logging list...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;logging list ASA_CRITICAL message &amp;lt;#&amp;gt; : Single message id&lt;/P&gt;&lt;P&gt;logging list ASA_CRITICAL message &amp;lt;# - #&amp;gt; Range of messages&lt;/P&gt;&lt;P&gt;logging trap ASA_CRITICAL&lt;/P&gt;&lt;P&gt;logging from-address &lt;A href="mailto:RBD-ASA@silverpointcapital.com"&gt;ASA@companyname.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;logging recipient-address name&lt;A href="mailto:msheik@silverpointcapital.com"&gt;@comapnyname.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;smtp-server &lt;SERVER ip=""&gt;&lt;/SERVER&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With the config I use on my ASA, I receive emails for any commands run on ASA and when the user (not the VPN user, &lt;/P&gt;&lt;P&gt;but the ASA logged in admin) logged out etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hth&lt;/P&gt;&lt;P&gt;MS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Jul 2011 20:31:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-connection-log-activity/m-p/1698748#M534749</guid>
      <dc:creator>mvsheik123</dc:creator>
      <dc:date>2011-07-29T20:31:22Z</dc:date>
    </item>
  </channel>
</rss>

