This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

cannot monitor cisco any connect VPN users with UTM 9.5

Hi there,

currently no log can be found for user who connected to any Cisco anyconnect servers even bandwidth usage log. It seems that they completely bypassed the firewall. any suggestion?

Thanks,



This thread was automatically locked due to age.
Parents
  • Mahmood, if you're asking about users that connected to the UTM's 'Cisco VPN Client' Remote Access, look in the IPsec log and in 'Logging & Reporting >> Remote Access'.  If you didn't find what you need, please explain what question you're trying to get an answer for.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply
  • Mahmood, if you're asking about users that connected to the UTM's 'Cisco VPN Client' Remote Access, look in the IPsec log and in 'Logging & Reporting >> Remote Access'.  If you didn't find what you need, please explain what question you're trying to get an answer for.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Children
  • Bob, thank you for the the reply. Actually I meant that the users behind the firewall who connected to a third party Cisco any connect servers. Since we have lots of restricted websites in our country, users usually use such tricks to bypass the restriction. 

  • Well, I'm philosophically opposed to such restrictions, but I suppose you must demonstrate an effort to comply with the law.  In 'Application Control', you can make a rule that blocks everything in 'VPN and Tunneling'.  Above that, make a rule that allows and logs accesses from specific IPs where people have demonstrated a valid need.  Alternatively, Allow and Log for everyone and you will be able to see any such activity in Logging & Reporting.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Bob, I am against any restriction either and do not have any obligation against users who try to bypass the restriction. but I do need to know such VPN users bandwidth usage. your solution works for any VPN application but not Cisco anyconnect.