Link to home
Start Free TrialLog in
Avatar of netcmh
netcmhFlag for United States of America

asked on

Cisco ASA alert on VPN

Hello,

I'm trying to setup an alert on successful VPN login attempts on my ASA 5520. I've not gotten far.

I have Clientless SSL VPN access enabled and working. I see the syslog events when some one logs in and out of the VPN.

How can I set up an email alert to be sent to me when this happens? I have alerts coming to me for critical events and I'd like to add this to my list.

Thank you.
Avatar of rauenpc
rauenpc
Flag of United States of America image

Below are the commands I used to send email alerts when the primary default route failed (triggered via SLA). I found the syslog error ID (622001) and changed the level to error, created a logging group with that message, and tied that group to the logging mail commands. You would just need to change this to the syslog error ID(s) that you see during logon/logoff. You may need to add an exception on your email server to allow the ASA to send the email.


logging enable
logging list InternetSLA message 622001
logging console errors
logging buffered informational
logging asdm informational
logging mail InternetSLA
logging from-address ASAFIREWALL@company.com
logging recipient-address chris@company.com level errors
logging message 622001 level errors

sla monitor 1
type echo protocol ipIcmpEcho x.x.x.5 interface outside
sla monitor schedule 1 life forever start-time now

smtp-server 172.20.0.10
Avatar of netcmh

ASKER

So, I already have alerts coming to me on critical events.

What I need is the ability to track VPN logins, in addition to the existing:

logging enable
logging timestamp
logging asdm-buffer-size 500
logging console errors
logging monitor debugging
logging buffered warnings
logging trap notifications
logging asdm warnings
logging mail alerts
logging from-address CiscoASA@mycompany.com
logging recipient-address admin@mycompany.com level errors
logging host inside NetAdminPC
logging class vpn trap informational
no logging message 106015
no logging message 313001
no logging message 313008
no logging message 106023
no logging message 710003
no logging message 106100
no logging message 505013
no logging message 505015
no logging message 302015
no logging message 302014
no logging message 302013
no logging message 302018
no logging message 302017
no logging message 302016
no logging message 302021
no logging message 302020

How do I proceed?

Thanks
ASKER CERTIFIED SOLUTION
Avatar of rauenpc
rauenpc
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial