• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Syslog openvpn

Scheduled Pinned Locked Moved OpenVPN
10 Posts 3 Posters 916 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • T
    tunge2
    last edited by Mar 23, 2020, 11:22 AM

    I want to see the users that logon and logoff from/with Openvpn on our Pfsense machine. (they connect with cerificates) I do not see any authenticated log rules. The rest i see in our syslog file

    I have made an export to syslog (export pfsense-Openvpn log.)

    1 Reply Last reply Reply Quote 0
    • G
      Gertjan
      last edited by Mar 23, 2020, 2:00 PM

      @tunge2 said in Syslog openvpn:

      I want to see

      Ask OpenVPN to show the details.
      Like :

      5621655d-df93-4625-ac26-2e657f1d6552-image.png

      to the maximum value.
      Expect a lot of details.

      No "help me" PM's please. Use the forum, the community will thank you.
      Edit : and where are the logs ??

      T 1 Reply Last reply Mar 23, 2020, 2:47 PM Reply Quote 0
      • T
        tunge2 @Gertjan
        last edited by Mar 23, 2020, 2:47 PM

        @Gertjan Thank You

        Thats a lot of information but not al little overkill
        . It still not clear on when a user exactly connect and disconnect

        G 1 Reply Last reply Mar 23, 2020, 3:03 PM Reply Quote 0
        • R
          Rico LAYER 8 Rebel Alliance
          last edited by Mar 23, 2020, 3:02 PM

          With the OpenVPN RAS Verbosity Level set to default I see those two lines after a User authenticated successfully:

          Mar 23 15:57:01 	openvpn 	62926 	CLIENTIP:CLIENTPORT [USERNAME] Peer Connection Initiated with [AF_INET]CLIENTIP:CLIENTPORT
          Mar 23 15:57:01 	openvpn 		user 'USERNAME' authenticated 
          

          -Rico

          T 1 Reply Last reply Mar 23, 2020, 3:10 PM Reply Quote 0
          • G
            Gertjan @tunge2
            last edited by Mar 23, 2020, 3:03 PM

            @tunge2 said in Syslog openvpn:

            It still not clear on when a user exactly connect and disconnect

            Have a look here.
            Very recently, some threads discussed just that : VPN connect and disconnect notifications. SEnd to you by mail, etc.

            No "help me" PM's please. Use the forum, the community will thank you.
            Edit : and where are the logs ??

            1 Reply Last reply Reply Quote 0
            • R
              Rico LAYER 8 Rebel Alliance
              last edited by Rico Mar 23, 2020, 3:09 PM Mar 23, 2020, 3:08 PM

              Log with a matching User/Cert but wrong password:

              Mar 23 16:02:42 	openvpn 		user 'USERNAME' could not authenticate. 
              

              Log with a wrong (unknown) User:

              Mar 23 16:05:15 	openvpn 		Username does not match certificate common name (WRONGUSER != USERNAME), access denied. 
              

              -Rico

              T 1 Reply Last reply Mar 23, 2020, 3:12 PM Reply Quote 0
              • T
                tunge2 @Rico
                last edited by Mar 23, 2020, 3:10 PM

                @Rico the first line i found. the second log line i did not found.
                The connect line is found.
                But the disconnect line in the logfile is not so clear
                the only rule is this one. The problem is that i does not say the username. Only that some one disconnects.

                Logfile Openvpn
                openvpn[42273]: MANAGEMENT: Client disconnected

                1 Reply Last reply Reply Quote 0
                • T
                  tunge2 @Rico
                  last edited by Mar 23, 2020, 3:12 PM

                  @Rico we only use certificates without the username part.

                  1 Reply Last reply Reply Quote 0
                  • G
                    Gertjan
                    last edited by Mar 23, 2020, 3:53 PM

                    Found it : https://forum.netgate.com/topic/151351/email-notification-openvpn-client-connect-common-name

                    No "help me" PM's please. Use the forum, the community will thank you.
                    Edit : and where are the logs ??

                    T 1 Reply Last reply Mar 23, 2020, 5:15 PM Reply Quote 1
                    • T
                      tunge2 @Gertjan
                      last edited by Mar 23, 2020, 5:15 PM

                      @Gertjan but thats different right? i use syslog and not direct php on the pfsense system

                      1 Reply Last reply Reply Quote 0
                      10 out of 10
                      • First post
                        10/10
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                        This community forum collects and processes your personal information.
                        consent.not_received