VPN Events Reports

To search for and generate a report on Cisco VPN, Check Point VPN, Nortel VPN, or RADIUS syslog messages of the System Message type for selected log sources during a specified time interval, use the VPN Events Real-Time Report.

Menu path: Reports > Operational > VPN Events

In addition to setting the common report options in Preparing a Real-time Report, you can select optional filter operators in the generated report.

By default, the following options are all selected.

For information on saving the generated report, see Formats for Saving a Generated Report.

VPN Events Report - Optional Filter Operators
Option Description
Time Time the syslog message was generated
Source Device IP address of the device originating the connection
Group VPN group name
User VPN user ID
Public IP Public IP address originating the VPN connection
Severity Severity Code associated with the message
Code Code number of the system message
Area Name of the defined VPN area
Detail Message Text of the syslog message

Appliances cannot receive disconnected messages. A VPN session is recorded permanently in the database table authentication after it is disconnected, prior to that the session is considered active. A Check Point VPN session is considered disconnected when a new connection attempt is made by the same user from the same IP address.