Monitoring live VPN sessions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-29-2024 05:05 AM
Hello
We need to monitor RA VPN session live traffic per user.
FMC shows VPN data only at the end of the session.
All needed information we have in CLI with command "show vpn-sessiondb anyconnect", but thats is not comfortable every time do ssh connection.
Also it would be great to have some dashboard with graphs, where we can see vpn users data usage.
We use FTD 2130.
- Labels:
-
Other VPN Topics
-
Remote Access
-
VPN
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-08-2024 11:01 PM
FMC 7.3 i beleive started the support for it..
7.4 has for it sure
what version are you running ?
CCIEx2
Freelance consultant
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-09-2024 11:57 PM
Hello,
We have 7.2.5 version.
Yeah, 7.3 and above can help. Thanks.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-10-2024 12:21 AM
yeah but it doesnt have real time traffic stats per user.. please see my response about using the SNMP mib.. that may be the best option... ofcourse you can regular CLI to parse and dump it to a file/database and show in a nice gui.. not very difficult...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-10-2024 12:53 AM
I tried to get information using SNMP mibs + Zabbix.
I managed to get information about number of vpn session.
But further I faced some troubles. My goal was to get just 3 parameters: Username, Session packets IN and OUT.
First of all, for every snmp oid request, FTD response with 3 lines per user:
SNMPv2-SMI::enterprises.9.9.392.1.3.21.1.1.20.100.116.111.100.111.114.101.110.107.111.64.77.79.70.46.76.79.67.65.76.518254593 = STRING: "jsmith"
SNMPv2-SMI::enterprises.9.9.392.1.3.21.1.1.20.100.116.111.100.111.114.101.110.107.111.64.77.79.70.46.76.79.67.65.76.518254594 = STRING: "jsmith"
SNMPv2-SMI::enterprises.9.9.392.1.3.21.1.1.20.100.116.111.100.111.114.101.110.107.111.64.77.79.70.46.76.79.67.65.76.518254595 = STRING: "jsmith"
Second of all, when I tried to preprocessing that output on Zabbix, to cut 2 lines of 3, it wasn't work.
The same situation for snmp oids for user traffic.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-10-2024 09:24 AM
i dont have a firewall in the lab at the moment.. but you may want to do a snmp walk to see what is out there... as per the MIB doc, that data is there...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-08-2024 11:33 PM
We need to monitor RA VPN session live traffic per user.
Personally not seen on the GUI (may be i have missed dont know) Live Traffic per user - not possible.
Either you need to make a tool dump the command line Realtime and make own graphs. (but if you have huge users that will be very heavy task)
what is the use case - instead you can monitor the RAVPN traffic traversing the interface monitor using NMS see any bottle neck.
Also it would be great to have some dashboard with graphs, where we can see vpn users data usage.
You can generate reports -
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-10-2024 12:07 AM
Our solution at the moment is to use Stealthwatch.
It has almost everything we need to monitor users vpn activity.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-10-2024 12:23 AM
yes sw (or cisco secure analytics - current name) will work as long as they can buy another product...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-10-2024 10:48 PM
Sure if you can send the flows to Stealthwatch you can get any useful information or using any other tools like Grafana will help you.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-09-2024 12:31 AM
your right the new dashboard still does not have per user...
i think the best bet is to use a SNMP poll and you do a more agressive poll or ondemand poll to get latest data:
https://github.com/taishin/vendor_mibs/blob/master/CISCO-REMOTE-ACCESS-MONITOR-MIB.my
i have not tried but the mib does show per user traffic.
