Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Troubles with tracking activities of a user

Dear Community,

i’m forced with tracking some users behavior, especially if and which private sites they access from their company PC (i.e. youtube, etc.)

I stumbled upon some problems though.

My general understanding is, that the first thing to look at is the „Log Viewer/Web Filter“. When i access that i see all the entries, but the „username“ field is not populated. I do see all users though when i look at "Authentication - Users" with their username, so the firewall knows them.

I looked around for a solution and it was mentioned, that the „Match known users“ box need to be ticked for usernames to appear in the Logviewer, so i did that at the last „default communication“ rule under „Rules and policies“, which allows everything that is not blocked by another rule before.

To my understanding this „Match known users“ uses the „Any“ group (which is already ticked by default in the „User or groups“ list), but as soon as i save that change, my own user account got blocked from accessing any website in the browser, which probably means i would block the access for every user.

My question here: Does „any“ not work in that scenario? When i click on „Add new item“ i see all user accounts and if remove the checkbox from „Any“ here, i can select users individually. Is that the way to go here, to select every user manually? Or should "Any" work and i did something wrong before?


An additional question about the Logviewer: When i select the „Web filter“ and search i.e. for youtube i get results with Youtube in the referrer column and Youtube related links (like ytimg.com or googlevideo.com/videoplayback) in the URL column, but i not see the real URL the user has visited in the browser. Is there any way/another filter where i can access that information?


It was mentioned as well, that web activities are also visible under „Authentication“ - „Users“ - „View usage“, but to my understanding this shows only some general informations like Upload and Download traffic, right? I cannot get additional informations like visited URL’s here?


Thanks a lot for your help
Thomas



This thread was automatically locked due to age.
Parents
  • Hello,

    Thanks for reaching out to Sophos Community.

    Could you confirm if you could see the user/s under > Current Activities > Live users? and Log Viewer > Authentication (Please check for Status if Successful, Username, IP), Could you also verify if your authentication server is at the top list of Authentication > Servers

    May you also share your Firewall and Web Filter rule for this. Thank you

    Regards,

    Raphael Alganes
    Community Support Engineer | Sophos Technical Support
    Sophos Support Videos Product Documentation  |  @SophosSupport  | Sign up for SMS Alerts
    If a post solves your question use the 'Verify Answer' link.

  • Dear Raphael,

    thank you for your fast response.

    Under "Current Activities - Live Users" i can see users with their username, but i just noticed that i only see those users who are connected via VPN (as they all share the same IP address range).

    Under "Logviewer - Authentication" i can see a lot of users, most of them from VPN due to the IP, but also some with local network IP address as they logon to "My Account" (probably for checking quarantined emails). Those have a successful status and have an IP address.

    What would you like to see? A screenshot from the final firewall rule, that allows everything not blocked before ?

    Thanks

    Thomas

Reply
  • Dear Raphael,

    thank you for your fast response.

    Under "Current Activities - Live Users" i can see users with their username, but i just noticed that i only see those users who are connected via VPN (as they all share the same IP address range).

    Under "Logviewer - Authentication" i can see a lot of users, most of them from VPN due to the IP, but also some with local network IP address as they logon to "My Account" (probably for checking quarantined emails). Those have a successful status and have an IP address.

    What would you like to see? A screenshot from the final firewall rule, that allows everything not blocked before ?

    Thanks

    Thomas

Children