- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- Re: Mobile Access Reporting
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Mobile Access Reporting
I am trying to figure out how to get mobile access to correctly report on users for:
1. Login/Logout Activity
2. Client they are currently using
3. Destination of their traffic
Firsts 2 I have been successful in creating the appropriate pages. However the 3rd doesn't seem to work no matter what I do.
On SmartEvent I created a new report with report filter as follows:
and on the page for my destinations I set the page with a table with settings as follows:
However no matter what I do the destination comes up blank:
Can someone enlighten me on what I'm doing wrong -have spent hours on the and if I put in "Destination port" into the table settings that shows up, the only thing I cannot get to show up is "Destination"
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Juan,
Try to add "contains" field and match the words. Let see if you are getting reports or not for destination.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
"No data found" when I change my filter.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Which destination are you looking for here:
- The gateway the user is authenticating
- The server they are connecting to over the VPN
- Something else
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The server they are connecting to over vpn.
Sent from my iPhone
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I found the issue it's not allowing VPN traffic data to be pulled into table view, is this by design??
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Jaun,
Are you talking about Mobile access SSL VPN? Please select "All Session events" in Mobile access blade for required field and check.
Mobile Access Blade --> Advance setting --> Logging --> Tracking
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Not sure what you’re referring to there but I have logs reported for user access:
there is just no way to get them pulled into the reports because VPN Blade is not an option for data field:
--Juan
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Please add a screen capture of a sample log card and mark all the relevant fields you wish to report on.
Then I will be able to advise you how to do it.
Kfir
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Still trying to get this resolved:
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Just a thought, have you tried applying a report filter of VPN blade and Source equal to the Office mode IP range, and then adding just source and destination to your table?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes doesn’t come up ☺
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
What version are the gateways and management on?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
R80.10 – mobile access is not one of the fields you can add in the table
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Just dealing with such report and have follwing suggestions for you:
1. Enable "logging per session" on all rules you want to track. VPN blade is not generating session logs, so no data for smartevent.
2. On your report use filter by action: Decrypt and can also filter for destination if applicable.
Where how it looks no my report:
Hope this helps
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank you very much - will test per your settings.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
That worked!! Thanks so much for the solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
I've read this thread with interest as I'm trying to do the same thing - reporting on what internal servers each Mobile Access user is hitting. I didn't quite follow when you suggested "logging per session". I presume you mean on the normal Security rules logging? In which case, which Security rule would I log to capture Mobile Access Native Application traffic?
Any help greatly appreciated.
Thanks,
Matt
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Right click on Track field of relevant rule, select More.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks Dameon Welch Abernathy. I was more interested in which Security rule I need to enable this logging. I thought that as I'm using Mobile Access, my access rules are created in the MAB rulebase rather than the Security rulebase, so I don't get which specific rule I should enable this per session logging on in order to capture what internal "Native Application" IP's my users are accessing?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Which Security rule (if any) matches the traffic?
Not sure if this works if you're not using the unified policy that includes Mobile Access or not.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Ah, Unified Policy! That makes sense... I'm not running Unified at the moment... I'll add that to my To-Do list!
Thanks.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
I have made below settings for only Mobile users.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I have put Office pool IPs in source field.
