Sophos XGS (SFOS 20.0.1 MR-1-Build342)
Is it possible to know the total time user has been connected to the vpn as I can only get the authentication and data transferred.
Added TAGs
[edited by: Erick Jan at 10:38 AM (GMT -7) on 19 Aug 2024]
Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.
Sophos XGS (SFOS 20.0.1 MR-1-Build342)
Is it possible to know the total time user has been connected to the vpn as I can only get the authentication and data transferred.
Thanks for your reply, however in the reports they only display the total data transferred.
you can create your own report from the live logs from login and disconnect times.
also you can import that as CSV in excel.
Also in Reports you can filter Auth events.
But I'm not aware if a bulid-in report exists for SSL VPN duration. I also see no need for such a report.
You could also check CFR (Central Firewall Reporting). It includes a Connection time report.
__________________________________________________________________________________________________________________
Hi LuCar Toni I syced the fw to the central firewall reporting however only the red is being displayed and not the actual ssl users
thanks for your reply LHerzog however with the above you can only see when they logged in to the vpn. I need also the time when they logged out.
They just want to know how long they were connected to the vpn and I will be asked this report frequently so the easier it is the better.
thanks for your reply LHerzog however with the above you can only see when they logged in to the vpn. I need also the time when they logged out.
They just want to know how long they were connected to the vpn and I will be asked this report frequently so the easier it is the better.
ah, that was, what you asked for but the logout time can be seen also from the authentication events.
all in all this would be only useful to track down a login/logout events for a few users, nothing to automate.
2024-09-19 13:44:34,Firewall Authentication,Information,User xxx@xxx.de was logged out of firewall
that can also be pulled from central logging.
you can assume that if the User IP address is from your VPN Range and see a logout, that this is the termination of the VPN Session