cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1364
Views
0
Helpful
2
Replies

LMS 3.2 VPN syslogs from ASA

xs.gautam
Level 1
Level 1

Hi All,

Can we configure LMS 3.2 to collect syslog till Severity level 6 (Informational) and enable the specific below

logs such as (whatever is possible) from Cisco ASA:

i. VPN ID

ii. Source Public IP

iii. IP assigned by DHCP Server to Remote VPN Client

iv. Connect Time (Login)

v. Disconnect Time (Logout)

vi. IPs accessed during the session (IP Accounting)

Also if we could be able to generate syslog reports for above VPN logs from LMS.

Regards

Gautam Patel

2 Replies 2

xs.gautam
Level 1
Level 1

I would really appreciate if someone can answer the above queries.

I have tried logging few syslog messages on lms for "vpnc" class but i dont see all messages in syslog.log file.

Does LMS filters messages before logging in syslog.log file from ASA ?

Update:

I am able to log VPN activity syslog messages in LMS 3.2, by creating a list containing messages id's.

But So far a few details that i am not able to capture is IP Authorization permitted messages for IP Accounting. ( Syslog ID:109007)

Can you please help here ?

Regards

Gautam Patel

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: