- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-12-2024 02:53 PM
I'm trying to figure out how to display user authentication attempts for VPN success/failures. I can see successful logins but not sure where to go to show failed login attempts. I have configured a Flexconfig Object to not hide username. Just trying to figure out how to show that in Secure FMC.
Thanks,
David
Solved! Go to Solution.
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-12-2024 08:13 PM
See the VPN Troubleshooting section (under the Device menu). You can filter there to show only failed attempts if so desired.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-12-2024 03:19 PM
Try this way
Check message ID (failed auth) and add it to event list
MHM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-12-2024 08:13 PM
See the VPN Troubleshooting section (under the Device menu). You can filter there to show only failed attempts if so desired.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-13-2024 07:08 PM
Thanks, that works! It would be nice to add this to a dashboard.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-14-2024 12:19 AM
Solved: Authentication Attempts Logs On FTD FirePOWER 2130 or FTD Cisco ISA 3000 - Cisco Community
did you ever try my suggestion ??
MHM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-15-2024 06:43 AM
I wasn't sure where in FMC to search.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-14-2024 05:04 AM
@davparker I'm not sure how to build a dashboard for it, but it's relatively easy to make a report. When you have the troubleshooting page open, just click on reporting and customize it to suit. Here is a filter for rejected users:
You can generate that on-demand or schedule it to run daily etc. and optionally email it to you. Here's an example of what the rpoert PDF looks like (device name redacted):
