09-02-2010 03:25 AM - edited 02-21-2020 04:04 AM
Hi All,
Can we configure LMS 3.2 to collect syslog till Severity level 6 (Informational) and enable the specific below
logs such as (whatever is possible) from Cisco ASA:
i. VPN ID
ii. Source Public IP
iii. IP assigned by DHCP Server to Remote VPN Client
iv. Connect Time (Login)
v. Disconnect Time (Logout)
vi. IPs accessed during the session (IP Accounting)
Also if we could be able to generate syslog reports for above VPN logs from LMS.
Regards
Gautam Patel
09-07-2010 11:13 PM
I would really appreciate if someone can answer the above queries.
I have tried logging few syslog messages on lms for "vpnc" class but i dont see all messages in syslog.log file.
Does LMS filters messages before logging in syslog.log file from ASA ?
09-10-2010 12:03 AM
Update:
I am able to log VPN activity syslog messages in LMS 3.2, by creating a list containing messages id's.
But So far a few details that i am not able to capture is IP Authorization permitted messages for IP Accounting. ( Syslog ID:109007)
Can you please help here ?
Regards
Gautam Patel
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide