cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
453
Views
5
Helpful
3
Replies

How to audit successful logins from 3000 concentrator

PaulWelc
Level 1
Level 1

I'm trying to find out where in the 3000 concentrator I can turn on auditing of successful logins to send to my syslog server (MARS) so I can run a report from last month to see who is logging in remotely. Thanks in advance!

3 Replies 3

chrisd
Level 1
Level 1

Hi Paul

You dont mention what authentication method you are using or type of vpn session (IPSEC or SSL)

I`ve not had chance to test this, but looking at the Events for the Concentrator...

VPN Concentrator

Configuration>System>Events>General

Select the Events to Syslog Field, Usually 1-5 for MARS.

In MARS

Event ID: 7002776

Event Type Details: Cisco VPN Authentication successful

This event indicates that an authentication request has been successful. The event text will point to the server and user ID.

Report: COBIT DS5.2: Authentication and Access

Activity: Remote Access Login - Top User (Total View)

Looking at the event types for this report...

Info/SuccessfulLogin/AAA, you may need to be using Cisco ACS for Authentication.

Hi Chris, I'm using IPSEC with group names (may have a group called IT that has 3 users in that group). I have it setup the way you describe, but I don't see anything in MARS. In MARS I run the report "This report ranks users by remote access logins (PPP, L2TP, PPTP, IPSec)." and the report is blank (no users or groups). I double checked to make sure the syslog server is pointed to the MARS IP address. Thanks

Hi Paul

If you run a query, on RAW Event, from just the Concentrator (over the last hour or so, or real-time) do you see any events coming in?

Chris

ciscomars.blogspot.com