<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Correlate VPN User to IP in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/correlate-vpn-user-to-ip/m-p/14885#M10928</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;+1 on desire to have the VPN user logged in the User field in the Traffic log&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 05 Aug 2011 18:12:41 GMT</pubDate>
    <dc:creator>frank_henry</dc:creator>
    <dc:date>2011-08-05T18:12:41Z</dc:date>
    <item>
      <title>Correlate VPN User to IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/correlate-vpn-user-to-ip/m-p/14880#M10923</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is there currently an easy way to Correlate a VPN user in trafic logs with the IP the user authenticated from?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For now I am having to view the traffic in the Traffic log note the user then goto the System logs and correlate the date / time of the VPN login go see the IP they authenticated from.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Michael&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Apr 2010 22:02:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/correlate-vpn-user-to-ip/m-p/14880#M10923</guid>
      <dc:creator>SoftwareMedia</dc:creator>
      <dc:date>2010-04-13T22:02:55Z</dc:date>
    </item>
    <item>
      <title>Re: Correlate VPN User to IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/correlate-vpn-user-to-ip/m-p/14881#M10924</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you create a zone for your VPN users, you can filter on that zone name in the traffic log to quickly view the VPN users and their source addresses.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Apr 2010 02:44:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/correlate-vpn-user-to-ip/m-p/14881#M10924</guid>
      <dc:creator>nrice</dc:creator>
      <dc:date>2010-04-15T02:44:41Z</dc:date>
    </item>
    <item>
      <title>Re: Correlate VPN User to IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/correlate-vpn-user-to-ip/m-p/14882#M10925</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Maybe I have something configured wrong. While that does produce an easy filter to see VPN users and their IP it shows the address the users has been assigned from the VPN Address pool (172.16.1.1/25) I am wanting to see the IP address of the machine that the user authenticated from.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In System logs with Filter set to: (eventid eq sslvpn-regist-succ)&lt;/P&gt;&lt;P&gt;it shows the IP address the user authenticated from: (SSL VPN user login succeeded. Login from:&lt;STRONG&gt;75.152.213.61&lt;/STRONG&gt;, User name: USER.)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trying to correlate 75.152.213.61 to&lt;STRONG&gt; &lt;/STRONG&gt;172.16.1.1 to USER in the traffic logs for a given date / time without having to jump back and forth from Traffic logs and System logs. Most of my VPN users login from a static or near static IP (IP changes once ever 3 months) for all my efforts to educate they are still very careless with their credential, leaving them on postit notes and the like for anyone to see. If I can easily correlate USER to the IP they authenticate from it makes it easier to determine if their credentials have been compromised.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Michael&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Apr 2010 17:07:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/correlate-vpn-user-to-ip/m-p/14882#M10925</guid>
      <dc:creator>SoftwareMedia</dc:creator>
      <dc:date>2010-04-20T17:07:36Z</dc:date>
    </item>
    <item>
      <title>Re: Correlate VPN User to IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/correlate-vpn-user-to-ip/m-p/14883#M10926</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Michael,&lt;/P&gt;&lt;P&gt;I believe the command that you are looking is found in the cli and it is as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; show ssl-vpn current-user&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;&lt;P&gt;Stephen&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Apr 2010 20:44:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/correlate-vpn-user-to-ip/m-p/14883#M10926</guid>
      <dc:creator>swhyte</dc:creator>
      <dc:date>2010-04-20T20:44:41Z</dc:date>
    </item>
    <item>
      <title>Re: Correlate VPN User to IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/correlate-vpn-user-to-ip/m-p/14884#M10927</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the tip!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; show ssl-vpn current-user&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Does exactly what I am looking for, for currently logged in users. I am also very interested in getting that same view from the logs. It would allow me to audit VPN access very quickly.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 May 2010 19:21:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/correlate-vpn-user-to-ip/m-p/14884#M10927</guid>
      <dc:creator>SoftwareMedia</dc:creator>
      <dc:date>2010-05-11T19:21:35Z</dc:date>
    </item>
    <item>
      <title>Re: Correlate VPN User to IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/correlate-vpn-user-to-ip/m-p/14885#M10928</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;+1 on desire to have the VPN user logged in the User field in the Traffic log&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Aug 2011 18:12:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/correlate-vpn-user-to-ip/m-p/14885#M10928</guid>
      <dc:creator>frank_henry</dc:creator>
      <dc:date>2011-08-05T18:12:41Z</dc:date>
    </item>
    <item>
      <title>Re: Correlate VPN User to IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/correlate-vpn-user-to-ip/m-p/14886#M10929</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Enable user identification in the zone where you have your tunnel interface (for the SSLVPN portal) and specify the IP-pool network as well. After that you should have your SSLVPN users in ACC/Log&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Aug 2011 07:09:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/correlate-vpn-user-to-ip/m-p/14886#M10929</guid>
      <dc:creator>rapoint_person</dc:creator>
      <dc:date>2011-08-08T07:09:52Z</dc:date>
    </item>
  </channel>
</rss>

