<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Monitor VPN Access in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/monitor-vpn-access/m-p/1223882#M876973</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Joshua&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are a number of messages that are generated by an ASA when a user connects using the VPN client to create an IPSec connection. You could use these to monitor and log VPN access. One of the many messages that you might consider to watch the establishment of the session is this one which marks the end of initial IPSec negotiation:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Feb 02 2009 15:40:30: %ASA-5-713120: Group = testgrp, Username = rburts, IP = 200.200.200.2, PHASE 2 COMPLETED (msgid=43a2a86b)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A message that you might consider to watch for ending of sessions is this one which gives the session duration as well as the timestamp of the event:&lt;/P&gt;&lt;P&gt;Feb 02 2009 15:40:44: %ASA-4-113019: Group = testgrp, Username = rburts, IP = 200.200.200.2, Session disconnected. Session Type: IPsec, Duration: 0h:00m:26s, Bytes xmt: 0, Bytes rcv: 3187, Reason: User Requested&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 02 Feb 2009 20:55:50 GMT</pubDate>
    <dc:creator>Richard Burts</dc:creator>
    <dc:date>2009-02-02T20:55:50Z</dc:date>
    <item>
      <title>Monitor VPN Access</title>
      <link>https://community.cisco.com/t5/network-security/monitor-vpn-access/m-p/1223881#M876970</link>
      <description>&lt;P&gt;Can you monitor and log VPN access to a PIX or ASA? I would like to who and when the users connect a VPN tunnel.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am assuming that you can but I can't find any documentation. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 14:44:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/monitor-vpn-access/m-p/1223881#M876970</guid>
      <dc:creator>jmaurer1205</dc:creator>
      <dc:date>2019-03-11T14:44:46Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor VPN Access</title>
      <link>https://community.cisco.com/t5/network-security/monitor-vpn-access/m-p/1223882#M876973</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Joshua&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are a number of messages that are generated by an ASA when a user connects using the VPN client to create an IPSec connection. You could use these to monitor and log VPN access. One of the many messages that you might consider to watch the establishment of the session is this one which marks the end of initial IPSec negotiation:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Feb 02 2009 15:40:30: %ASA-5-713120: Group = testgrp, Username = rburts, IP = 200.200.200.2, PHASE 2 COMPLETED (msgid=43a2a86b)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A message that you might consider to watch for ending of sessions is this one which gives the session duration as well as the timestamp of the event:&lt;/P&gt;&lt;P&gt;Feb 02 2009 15:40:44: %ASA-4-113019: Group = testgrp, Username = rburts, IP = 200.200.200.2, Session disconnected. Session Type: IPsec, Duration: 0h:00m:26s, Bytes xmt: 0, Bytes rcv: 3187, Reason: User Requested&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Feb 2009 20:55:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/monitor-vpn-access/m-p/1223882#M876973</guid>
      <dc:creator>Richard Burts</dc:creator>
      <dc:date>2009-02-02T20:55:50Z</dc:date>
    </item>
    <item>
      <title>Monitor VPN Access</title>
      <link>https://community.cisco.com/t5/network-security/monitor-vpn-access/m-p/1223883#M876976</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;P&gt;Check &lt;/P&gt;&lt;P&gt;&lt;A href="http://www.vpnttg.com/"&gt;http://www.vpnttg.com/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Advantage&amp;nbsp;&amp;nbsp; of VPNTTG over other SNMP based monitoring software’s is&amp;nbsp; following:&amp;nbsp;&amp;nbsp; Other (commonly used) software’s are working with static OID&amp;nbsp; numbers,&amp;nbsp;&amp;nbsp; i.e. whenever tunnel disconnects and reconnects, it gets&amp;nbsp; assigned a&amp;nbsp; new&amp;nbsp; OID number. This means that the historical data, gathered&amp;nbsp; on the&amp;nbsp;&amp;nbsp; connection, is lost each time. However, VPNTTG works with VPN&amp;nbsp; peer’s&amp;nbsp; IP&amp;nbsp; address and it stores for each VPN tunnel historical&amp;nbsp; monitoring&amp;nbsp; data&amp;nbsp; into the SQL server and into the RRD (Round Robin&amp;nbsp; Database) file.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Jul 2011 08:43:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/monitor-vpn-access/m-p/1223883#M876976</guid>
      <dc:creator>merabtavart</dc:creator>
      <dc:date>2011-07-22T08:43:08Z</dc:date>
    </item>
  </channel>
</rss>

