Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Syslog openvpn

    Scheduled Pinned Locked Moved OpenVPN
    10 Posts 3 Posters 842 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T
      tunge2
      last edited by

      I want to see the users that logon and logoff from/with Openvpn on our Pfsense machine. (they connect with cerificates) I do not see any authenticated log rules. The rest i see in our syslog file

      I have made an export to syslog (export pfsense-Openvpn log.)

      1 Reply Last reply Reply Quote 0
      • GertjanG
        Gertjan
        last edited by

        @tunge2 said in Syslog openvpn:

        I want to see

        Ask OpenVPN to show the details.
        Like :

        5621655d-df93-4625-ac26-2e657f1d6552-image.png

        to the maximum value.
        Expect a lot of details.

        No "help me" PM's please. Use the forum, the community will thank you.
        Edit : and where are the logs ??

        T 1 Reply Last reply Reply Quote 0
        • T
          tunge2 @Gertjan
          last edited by

          @Gertjan Thank You

          Thats a lot of information but not al little overkill
          . It still not clear on when a user exactly connect and disconnect

          GertjanG 1 Reply Last reply Reply Quote 0
          • RicoR
            Rico LAYER 8 Rebel Alliance
            last edited by

            With the OpenVPN RAS Verbosity Level set to default I see those two lines after a User authenticated successfully:

            Mar 23 15:57:01 	openvpn 	62926 	CLIENTIP:CLIENTPORT [USERNAME] Peer Connection Initiated with [AF_INET]CLIENTIP:CLIENTPORT
            Mar 23 15:57:01 	openvpn 		user 'USERNAME' authenticated 
            

            -Rico

            T 1 Reply Last reply Reply Quote 0
            • GertjanG
              Gertjan @tunge2
              last edited by

              @tunge2 said in Syslog openvpn:

              It still not clear on when a user exactly connect and disconnect

              Have a look here.
              Very recently, some threads discussed just that : VPN connect and disconnect notifications. SEnd to you by mail, etc.

              No "help me" PM's please. Use the forum, the community will thank you.
              Edit : and where are the logs ??

              1 Reply Last reply Reply Quote 0
              • RicoR
                Rico LAYER 8 Rebel Alliance
                last edited by Rico

                Log with a matching User/Cert but wrong password:

                Mar 23 16:02:42 	openvpn 		user 'USERNAME' could not authenticate. 
                

                Log with a wrong (unknown) User:

                Mar 23 16:05:15 	openvpn 		Username does not match certificate common name (WRONGUSER != USERNAME), access denied. 
                

                -Rico

                T 1 Reply Last reply Reply Quote 0
                • T
                  tunge2 @Rico
                  last edited by

                  @Rico the first line i found. the second log line i did not found.
                  The connect line is found.
                  But the disconnect line in the logfile is not so clear
                  the only rule is this one. The problem is that i does not say the username. Only that some one disconnects.

                  Logfile Openvpn
                  openvpn[42273]: MANAGEMENT: Client disconnected

                  1 Reply Last reply Reply Quote 0
                  • T
                    tunge2 @Rico
                    last edited by

                    @Rico we only use certificates without the username part.

                    1 Reply Last reply Reply Quote 0
                    • GertjanG
                      Gertjan
                      last edited by

                      Found it : https://forum.netgate.com/topic/151351/email-notification-openvpn-client-connect-common-name

                      No "help me" PM's please. Use the forum, the community will thank you.
                      Edit : and where are the logs ??

                      T 1 Reply Last reply Reply Quote 1
                      • T
                        tunge2 @Gertjan
                        last edited by

                        @Gertjan but thats different right? i use syslog and not direct php on the pfsense system

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.