Solved

username in pix traffic log

Posted on 2006-06-25
5
361 Views
Last Modified: 2013-11-16
Dear Experts,

Consider the following logs from PIX

<166>May 23 2006 21:11:17: %PIX-6-302015: Built inbound UDP connection 12591 for outside:xxxx/1025 (xxxx/53) to inside:xxxx/53 (xxxx/53) (john)
<166>May 23 2006 21:11:17: %PIX-6-302016: Teardown UDP connection 12591 for outside:xxxx/1025 to inside:xxxx/53 duration 0:00:01 bytes 612 (john)

Above logs are part of some udp traffic. For some logs I am getting username here and for others I am not. John is the user who is connecting my network through VPN.  Now my question is in what conditions username will appear? Will I always get the username If the traffic is going thrugh VPN?

with regards,
Kumar

0
Comment
Question by:mskumar_apk
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
5 Comments
 
LVL 32

Accepted Solution

by:
rsivanandan earned 125 total points
ID: 16982425
Any connection authenticated through AAA will get username as per Cisco Documents. So your VPN user is getting authenticated through AAA mechanism and so the answer is YES.

Cheers,
Rajesh
0
 

Author Comment

by:mskumar_apk
ID: 17031017
Sorry for the late reply was out of office for a while. That is great answer. I verified that.

Like wise is there a way to find the amount of traffic that is going through VPN per user? What is the signature in the log that I can look for?

regards
Kumar
0
 
LVL 32

Expert Comment

by:rsivanandan
ID: 17031088
Hmm. that is a big question by itself and right on the top of my head I don't feel anything.

Can you open up another thread ?

Cheers,
Rajesh
0
 
LVL 32

Expert Comment

by:rsivanandan
ID: 17031117
Post the link to the other question here ? I'm not sure if you can do that for individual vpn connections but there are more experienced guys here and I'd like to watch.

Cheers,
Rajesh
0
 

Author Comment

by:mskumar_apk
ID: 17031163
Hi,

Here is the question.

http://www.experts-exchange.com/Security/Firewalls/Q_21906797.html

I'm not sure if you can do that for individual vpn connections but there are more experienced guys here and I'd like to watch.

If its not possible for individual connections, then what else we can do as for as VPN connections are concerned?

regards,
Kumar
0

Featured Post

Get 15 Days FREE Full-Featured Trial

Benefit from a mission critical IT monitoring with Monitis Premium or get it FREE for your entry level monitoring needs.
-Over 200,000 users
-More than 300,000 websites monitored
-Used in 197 countries
-Recommended by 98% of users

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

The DROP (Spamhaus Don't Route Or Peer List) is a small list of IP address ranges that have been stolen or hijacked from their rightful owners. The DROP list is not a DNS based list.  It is designed to be downloaded as a file, with primary intention…
When speed and performance are vital to revenue, companies must have complete confidence in their cloud environment.
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…

717 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question