VPN Events Reports
To search for and generate a report on Cisco VPN, Check Point VPN, Nortel VPN, or RADIUS syslog messages of the System Message type for selected log sources during a specified time interval, use the VPN Events Real-Time Report.
Menu path:
In addition to setting the common report options in Preparing a Real-time Report, you can select optional filter operators in the generated report.
By default, the following options are all selected.
For information on saving the generated report, see Formats for Saving a Generated Report.
Option | Description |
---|---|
Time | Time the syslog message was generated |
Source Device | IP address of the device originating the connection |
Group | VPN group name |
User | VPN user ID |
Public IP | Public IP address originating the VPN connection |
Severity | Severity Code associated with the message |
Code | Code number of the system message |
Area | Name of the defined VPN area |
Detail Message | Text of the syslog message |
Appliances cannot receive disconnected messages. A VPN session is recorded permanently in the database table authentication after it is disconnected, prior to that the session is considered active. A Check Point VPN session is considered disconnected when a new connection attempt is made by the same user from the same IP address.