Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
CheckMateME
Explorer

Is there any way to see the past Remote Access User Connections on a Quantum Spark 1550 Appliance?

We are trying to investigate some user activity and need to know who was connected to the VPN and at what times for the past month. Is there some CLI command or log file that we can use to get that information? The Appliance hasn't been rebooted in that time if that makes any difference.

0 Kudos
4 Replies
PhoneBoy
Admin
Admin

I presume each connection from a Remote Access user will show in the Security Logs.
I don't think you can access the logs from the CLI on an SMB device.

0 Kudos
G_W_Albrecht
Legend Legend
Legend

This is possible but complicated: Use logs from /var/log/log/local/and follow SMB security log files. You need e.g. a SMS in VM with Eval to rebuild the logs and then can export them in readable format using logexport.

Much easier to use Embedded GAiA WebGUI...

 

CCSE / CCTE / CCME / CCSM Elite / SMB Specialist
0 Kudos
CheckMateME
Explorer

Thanks. I took a look at your SMB security log files post but didn't really know what a GAiA SMS VM was. My best guess was Security Management Server and found https://support.checkpoint.com/results/download/124397 but wasn't sure.

If you know an easy way to filter the logs on the Embedded GAiA WebGUI I'd happily use that. The best I have come up with is to scroll down the security logs till all (enough) are loaded and then filter on "vpn" and look at the "User" in the details for every record.

0 Kudos
G_W_Albrecht
Legend Legend
Legend

Yes, as i wrote above, easiest way is to filter the security logs in Embedded GAiA WebGUI

CCSE / CCTE / CCME / CCSM Elite / SMB Specialist
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events