12-06-2016 10:19 PM
Hi,
We have Cisco ASA 5585-X firewall and we generally create local VPN user accounts on the ASA. Since we have been creating these since long, there are more than 500 user accounts existing on the ASA.
Now we need to know who all are actually using the VPN or who are the inactive accounts, so we can just clean the garbage from ASA.
Does anyone have any idea to pull out the reports from ASA to filter the inactive VPN users?
Thanks in advance !!
12-07-2016 12:44 AM
hi
this command a try
SH VPN-Sessiondb ANYconnect SORT INactivity
Username : li-jp Index : 72
Assigned IP : 172.16.10.36 Public IP : 223.104.5.234
Protocol : AnyConnect-Parent DTLS-Tunnel
License : AnyConnect Premium, AnyConnect for Mobile
Encryption : AnyConnect-Parent: (1)none DTLS-Tunnel: (1)AES128
Hashing : AnyConnect-Parent: (1)none DTLS-Tunnel: (1)SHA1
Bytes Tx : 5110 Bytes Rx : 2638
Group Policy : vpnpolicy Tunnel Group : vpntunnel
Login Time : 15:59:42 china Sat Dec 3 2016
Duration : 4d 0h:37m:51s
Inactivity : 4d 0h:35m:47s
NAC Result : Unknown
VLAN Mapping : N/A VLAN : none
Then enter this commande
vpn-sessiondb logoff name li-jp
I hope this helps!
12-07-2016 01:36 AM
Thank you for your revert ogerking@sohu.com :)
I tried these commands and it only shows the inactivity time of current logged-in users but I want to know the users who never logged in since 1 month or more, so such accounts can be deleted.
Is that possible in any case?
12-07-2016 05:31 PM
hi
I'm sorry I didn't help you,I look forward to the right answer,me too.
12-07-2016 07:31 PM
Hi Quikr_167,
If you are using the ASA with the local database for usernames and passwords there is not really a way to find out which user is completely inactive so you can remove it, in this case normally what is recommended will be use a server for authentication so you can keep track of the users (ACS, Windows Server). From the ASA perspective the best way to handle this will be removing the users as soon as you know they are not going to be used anymore.
Hope this info helps!!
Rate if helps you!!
-JP-
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide