On Mon, Oct 31, 2011 at 13:38:21, Antonio Soares wrote: > Access > > Thanks Ryan. I was reading about that feature and I don't see how the > session information is sent: > > http://www.cisco.com/en/US/docs/security/asa/asa84/configuration/guide > / > acces > s_idfw.html > > Do you have experience with this feature ? >
I haven't implemented yet, but it's supposed to take a syslog message like this: Oct 31 2011 13:40:25: %ASA-5-304001: 192.168.x.x Accessed URL 96.17.203.95:http://www.static-cisco.com/web/fw/tools/mbox/mbox.js And translate it to: Oct 31 2011 13:40:25: %ASA-5-304001: (rwest) Accessed URL 96.17.203.95:http://www.static-cisco.com/web/fw/tools/mbox/mbox.js Similar to what you see with your RA VPN users. I'll be testing 8.4.2 again shortly and let you know what my results are. -ryan _______________________________________________ cisco-nsp mailing list [email protected] https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/
