cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
20543
Views
0
Helpful
15
Replies

ASA 5520 VPN User Login History.

firefox111_2000
Level 1
Level 1

Hello.  We are using the ASA 5520 as Firewall and VPN gateway for remote access by employees and vendors.  Is there a way to view a history of VPN user logins?

We used to have (or we still have but no longer using it) th CVPN 3005.  This device keeps log files of all activities.  I miss having this capability in the ASA 5520.

Thanks for any suggestions on what to do to capture VPN logins in the ASA5520.

15 Replies 15

Todd Pula
Level 7
Level 7

You could enable accounting and send connection information to a RADIUS server for historical purposes.  If you are looking to view real-time active sessions details, you can utilize the "sh vpn-sessiondb" command from the CLI.  The same details can also be viewed from the Monitoring tab within ASDM.

Todd

Thanks.  I will look for configuration setting on how to enable accounting in ASDM.  Is this just for VPN activity or will it enable all activity?  If it is for all, this is going to be huge!

How is this done in ASDM?  Thanks.

Found it!  Thanks.

Is there anyway to enable the accounting of users to a syslog server?

Probably we need to be careful about terminology as we attempt to answer this. If you are truly looking for accounting records then syslog is not the way to achieve it. If you want to achieve a method in which you can find records that show that a user did login and use the Remote Access VPN then you should be able to achieve this using syslog. I implemented AnyConnect for a customer who had this requirement to identify user login to AnyConnect. I configured the ASA to send syslog to their server. Using tools on the server we could search the logs and find records that did identify user access via AnyConnect (I would frequently search for the log record where the user was assigned an IP address and we could then look for activity relative to that address).

HTH

Rick

HTH

Rick

Richard,

I have ASA 5540.  How would you setup a log file where the user was assigned an IP address and then we could look for activity relative to that address?  I would like the log file to be sent to the syslog server.

Please let me know if you need additional information.

Thanks.

I am not clear whether you are asking how to set up a log file or are asking how to send the syslog records to a syslog server. Can  you clarify what is the question?

HTH

Rick

HTH

Rick

Thanks so much for your prompt response, Richard.  I am asking to send the syslog records to a syslog server.

Please let me know if you have any questions or need additional information.

Thanks.

logging host inside 192.168.2.5

HTH

Rick

HTH

Rick

Thanks so much for your prompt response, Richard.  May I ask you another question?  My Syslog server is old.  I want to upgrade it.  Do you know of a good product?  Thanks.

Syslog server is not in my area of real expertise. Perhaps other readers in the forum are better equipped to make suggestions than I am.

HTH

Rick

HTH

Rick

Thanks Richard.

Syslog servers are pretty generic. A daemon on a Linux host can suffice to capture the plain text messages in a flat file.

If you're a Windows person, there is the SolarWinds Kiwi syslog server. It comes in a free version (basic capabilities with a GUI) and paid version (lets you filter and customize etc.). If you have the higher end SolarWinds NPM, it also includes these features.