09-02-2010 03:25 AM - edited 02-21-2020 04:04 AM
Hi All,
Can we configure LMS 3.2 to collect syslog till Severity level 6 (Informational) and enable the specific below
logs such as (whatever is possible) from Cisco ASA:
i. VPN ID
ii. Source Public IP
iii. IP assigned by DHCP Server to Remote VPN Client
iv. Connect Time (Login)
v. Disconnect Time (Logout)
vi. IPs accessed during the session (IP Accounting)
Also if we could be able to generate syslog reports for above VPN logs from LMS.
Regards
Gautam Patel
09-07-2010 11:13 PM
I would really appreciate if someone can answer the above queries.
I have tried logging few syslog messages on lms for "vpnc" class but i dont see all messages in syslog.log file.
Does LMS filters messages before logging in syslog.log file from ASA ?
09-10-2010 12:03 AM
Update:
I am able to log VPN activity syslog messages in LMS 3.2, by creating a list containing messages id's.
But So far a few details that i am not able to capture is IP Authorization permitted messages for IP Accounting. ( Syslog ID:109007)
Can you please help here ?
Regards
Gautam Patel
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: