cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
352
Views
4
Helpful
7
Replies

FTD RA VPN Logs

alex.f.
Level 1
Level 1

Hi,

I try to find some Information of Remote Access or Mail ingress/egress activities on an FTD 3110 Tech support file or the Device it self.

I don't have any access to the FMC.

 

1 Accepted Solution

Accepted Solutions

Thanks for the feedback, unfortunately I already suspected this.

We are currently trying to restore the FMC data.
But this may take a few more weeks.

View solution in original post

7 Replies 7

you want FTD always debug the connect from Anyconnect ?
MHM

alex.f.
Level 1
Level 1

hi,
my question is whether there is a possibility to extract connection information from the TechSupport file of an FTD afterwards, which provides information about malicious network activities to a device in the local network.

For example, I am looking for successful RA VPN dial-ins by users or access to certain ports.

 

Most historical logs (including the type you are asking about) are streamed to the managing FMC in near real time and then deleted on the local device.

Thanks for the feedback, unfortunately I already suspected this.

We are currently trying to restore the FMC data.
But this may take a few more weeks.

Did you check

Show vpn sessiondb anyconnect detail 

This can access from cli of ftd' it give you breif which user connect to your FTD know

MHM

The command "Show vpn sessiondb anyconnect detail" will only show current connections with details (such as username, user IP real address, assigned VPN address, connection profile, tunnel-group, duration etc.).

It will not show details of any previous sessions.

Thanks, but even FMC don't keep this info for long time (without external syslog). 

If user access via ssl vpn to ftd and it idle timeout is not end he can see it details via show vpn sessiondb. 

MHM

Review Cisco Networking for a $25 gift card