Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

username in pix traffic log

Posted on 2006-06-25
5
Medium Priority
?
375 Views
Last Modified: 2013-11-16
Dear Experts,

Consider the following logs from PIX

<166>May 23 2006 21:11:17: %PIX-6-302015: Built inbound UDP connection 12591 for outside:xxxx/1025 (xxxx/53) to inside:xxxx/53 (xxxx/53) (john)
<166>May 23 2006 21:11:17: %PIX-6-302016: Teardown UDP connection 12591 for outside:xxxx/1025 to inside:xxxx/53 duration 0:00:01 bytes 612 (john)

Above logs are part of some udp traffic. For some logs I am getting username here and for others I am not. John is the user who is connecting my network through VPN.  Now my question is in what conditions username will appear? Will I always get the username If the traffic is going thrugh VPN?

with regards,
Kumar

0
Comment
Question by:mskumar_apk
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
5 Comments
 
LVL 32

Accepted Solution

by:
rsivanandan earned 500 total points
ID: 16982425
Any connection authenticated through AAA will get username as per Cisco Documents. So your VPN user is getting authenticated through AAA mechanism and so the answer is YES.

Cheers,
Rajesh
0
 

Author Comment

by:mskumar_apk
ID: 17031017
Sorry for the late reply was out of office for a while. That is great answer. I verified that.

Like wise is there a way to find the amount of traffic that is going through VPN per user? What is the signature in the log that I can look for?

regards
Kumar
0
 
LVL 32

Expert Comment

by:rsivanandan
ID: 17031088
Hmm. that is a big question by itself and right on the top of my head I don't feel anything.

Can you open up another thread ?

Cheers,
Rajesh
0
 
LVL 32

Expert Comment

by:rsivanandan
ID: 17031117
Post the link to the other question here ? I'm not sure if you can do that for individual vpn connections but there are more experienced guys here and I'd like to watch.

Cheers,
Rajesh
0
 

Author Comment

by:mskumar_apk
ID: 17031163
Hi,

Here is the question.

http://www.experts-exchange.com/Security/Firewalls/Q_21906797.html

I'm not sure if you can do that for individual vpn connections but there are more experienced guys here and I'd like to watch.

If its not possible for individual connections, then what else we can do as for as VPN connections are concerned?

regards,
Kumar
0

Featured Post

Free learning courses: Active Directory Deep Dive

Get a firm grasp on your IT environment when you learn Active Directory best practices with Veeam! Watch all, or choose any amount, of this three-part webinar series to improve your skills. From the basics to virtualization and backup, we got you covered.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Exchange server is not supported in any cloud-hosted platform (other than Azure with Azure Premium Storage).
Many of the companies I’ve worked with have embraced cloud solutions due to their desire to “get out of the datacenter business.” The ability to achieve better security and availability, and the speed with which they are able to deploy, is far grea…
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…
Suggested Courses

636 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question