network monitoring

Hi, does any one know of some software that can record who log's onto the network internally and externally via a MS 2000 server VPN.
And record when they have logged off.
doesn't have to be much more complex.
cheers
LVL 1
total123Asked:
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

x
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

NAORCCommented:
why bother paying for 3rd party software???

Open event viewer on the server and look in the security log.  if your using a domain, it will show logon and logoff information.

If you look for events with the catagory "logon/logoff" and a username thats not "system" it will show the info you need...

any use?
0
total123Author Commented:
yeh, but will it log vpn logon's ?
0
NAORCCommented:
yes
0
Powerful Yet Easy-to-Use Network Monitoring

Identify excessive bandwidth utilization or unexpected application traffic with SolarWinds Bandwidth Analyzer Pack.

NAORCCommented:
*To Elabourate -

It logs any login attempt to that server.  Be it VPN, local or whatever.
0
total123Author Commented:
just looked at the security in event viewer, it doesn't show it. but it does on the 2003 terminal server. which doesn't control the domain.
Do i have to enable something on the SBS 2000
0
NAORCCommented:
No, not that i know of....

Sorry, out of ideas... it works for us and i dont know what else to suggest
0
total123Author Commented:
do you use 2000 ?
0
Dave-sysadmCommented:

Start > Run > Type

secpol.msc

Expand "Local Policies", and select audit.   The options on the right allow you select what is recorded in event viewer.   That should be sufficient.

Typing

usrmgr.exe

I believe will allow you to do the same for Domains, (under Policies > Audit).   I work on a NT4 Domain, so I could be wrong.   This option tracks events on all domain clients, rather than server interaction, so shouldn't apply in your case.
0
skags442Commented:
if you go into routing and remote access, there should be a remote access logging folder in the tree un remote access policies. there you should be able to turn on the logging, this should provid what you need, turn on all the logging options, and set your log file settings to your disire.
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Network Analysis

From novice to tech pro — start learning today.