Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Imzi
Explorer

last successful RA VPN login date/time

We have a Check Point 9200 Security Gateway with a VM-based Management Server, and Remote Access VPN is configured and operational.
We need to verify the last successful RA VPN connection date/time and the user's historical VPN session activity.
Please advise on the appropriate SmartConsole logs, CLI commands, or other recommended methods to validate the user's last active timeframe and connection history.

0 Kudos
7 Replies
simonemantovani
MVP Diamond CHKP MVP Diamond CHKP
MVP Diamond CHKP

Hello

as a first approach, you could start by creating report (under Logs and Events) for VPN logs that includes login action, etc.; by setting different timeframe for the report you'll be able to have historical information.

0 Kudos
PhoneBoy
Admin
Admin

Imzi
Explorer

Could you please help us obtain the date and time of the user’s last connection to the RA VPN?

0 Kudos
PhoneBoy
Admin
Admin

When a user logs in via Remote Access VPN, there will be one or more logs indicating this.
In the log view, the action should be "Log In" and the blade will indicate VPN or Mobile Access, depending on how the user connected.
To put that into a nice report, you will need SmartEvent or an external SIEM to correlate those logs.

0 Kudos
Imzi
Explorer

We have tried using SmartEvent to retrieve and analyze the user-related logs; however, the required user log details are not being displayed/available as expected.
Our requirement is to retrieve and review the logs for all disconnected Remote Access (RA) VPN users, including the relevant disconnect events/details, so that we can identify the reason for disconnection and take appropriate corrective action accordingly.
Could you please advise if there is an alternative method, CLI command, or Check Point utility that can be used to retrieve these logs? Additionally, please let us know if any specific debug commands or log files need to be collected for further analysis.
0 Kudos
PhoneBoy
Admin
Admin

I don't recall disconnects being explicitly logged as a "disconnect" can occur, e.g. as a result of a loss of physical connectivity on the client end, thus no way for the client to log it (except maybe locally).
If you want to know why a client disconnects, the only place that might be logged is on the client side.

As for why SmartEvent isn't pulling the data, what specific fields are you attempting to build reports based on?
Not all of them may be indexed, which may be why you can't build the desired report. 

0 Kudos
Lesley
MVP Platinum
MVP Platinum

Import this one and try to add the columns you wish to see in this report. It is a good base to start from:

https://community.checkpoint.com/t5/SmartEvent/Enhanced-VPN-Dashboard/m-p/252358#M65

-------
Please press "Accept as Solution" if my post solved it 🙂
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events