CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SecureClient/SecuRemote
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-02-28
Senior Member
 
Join Date: 2005-11-21
Location: Europe, Lithuania
Posts: 291
Rep Power: 4
Sergej has an average reputation (10+)
Default How to monitor and count connected RemoteAccess VPN User

Hi,

What is the available methods to count and monitor Remote Access VPN users? For example all users are VPN enabled by default. Authentication is done via active directory (but some customers use local authentication). How to count how much VPN users was connected same time, see who use VPN and who do not using, who are the top VPN users etc.
Is it only available via eventia reporter? Are you happy with Eventia VPN reports (does it always working). What minimum you need to perform to enable Eventia VPN reports on RemoteAccess users?

Share you experience please.
Reply With Quote
  #2 (permalink)  
Old 2006-02-28
Member
 
Join Date: 2006-01-09
Posts: 72
Rep Power: 3
ddarby1 has an average reputation (10+)
Default Re: How to monitor and count connected RemoteAccess VPN User

Hi Sergej,

I guess you know about using SmartView Monitor to see what Remote Users are currently connected, VPN stats, related traffic, etc.

I setup and used Eventia Reporter as part of CCSE study and so haven't used it in a live environment yet (I get the impression that not many people are yet).

However, it worked really well for me, clear very presentable, customisable historical reports - the sort of thing that management love.

It seems clear that in a high-traffic production environment you'd want to put in on a seperate, fast application server, as it looks to be a bit of a resource hog.

I put the Reporter Module on the Primary SmartCenter (& log) Server and the Eventia Reporter Server on another Windows Server.

Basically it has two kinds of databases, which it draws reports from, the 'Express' Reports are pulled from data collected by SmartView Monitor (will include VPN user, traffic usage, etc.). This data is quicker to run reports against.
The Standard Reports search through the entire database, which I think is the comprised of all the logs sent from the enforcement module (can become quite large over time). With this you get a more comprehesive set of data to report against.

I've used Microsoft ISA 2004 reports in a high throughput environment and they weren't bad, however I'd say that Eventia Reporter is much better/more comprehensive/customisable.

It might take a little while to setup your reports as you want them(I remember having quite a few with 'no data found' due to incorrect settings), but that was mainly due to me getting use to using it I guess.

Hope that wasn't too glowing, but it's the best I can come up with without having used it in production.
Reply With Quote
  #3 (permalink)  
Old 2008-03-12
Junior Member
 
Join Date: 2006-02-04
Posts: 22
Rep Power: 0
usman_a has an average reputation (10+)
Default Re: How to monitor and count connected RemoteAccess VPN User

are there any cli commands to check any users are connected at any give time?
__________________
I used to think a firewall was a borken router but now i know thats its a hub!
Reply With Quote
  #4 (permalink)  
Old 2008-03-28
Junior Member
 
Join Date: 2007-08-24
Posts: 1
Rep Power: 0
Firewall_Guy has an average reputation (10+)
Default Re: How to monitor and count connected RemoteAccess VPN User

Try the following command:

fw tab -t userc_key -s

The firewall will return the number of active SecuRemote connections under the #VALS column.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 14:39.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0