Juniper Networks SSL VPN Gateway
- What is Discovered and Monitored
- Event Types
- Rules
- Reports
- Configuration
- Sample Parsed Juniper Networks SSL VPN Syslog Messages
- Settings for Access Credentials
What is Discovered and Monitored
Protocol | Information Discovered | Metrics Collected | Used For |
---|---|---|---|
SNMP | |||
Syslog |
Event Types
In ADMIN > Device Support > Event Types, search for "junos_dynamic_vpn" to see the event types associated with this device.
Rules
There are no predefined rules for this device.
Reports
There are no predefined reports for this device.
Configuration
SNMP
- Log into your device with administrative credentials.
- Go to System > Log/Monitoring > SNMP.
- Under Agent Properties, enter
public
for Community.
Syslog
VPN Access Syslog
- Go to System > Log/Monitoring > User Access > Settings.
- Under Select Events to Log, select Login/logout, User Settings, and Network Connect.
- Under Syslog Servers, enter the IP address of your FortiSIEM virtual appliance, and set the Facility to LOCAL0.
- Click Save Changes.
Admin Access Syslog
- Go to System > Log/Monitoring > Admin Access > Settings.
- Under Select Events to Log, select Administrator changes, License Changes, and Administrator logins.
- Under Syslog Servers, enter the IP address of your FortiSIEM virtual appliance, and set the Facility to LOCAL0.
- Click Save Changes.
Sample Parsed Juniper Networks SSL VPN Syslog Messages
<134>Juniper: 2008-10-28 04:34:53 - ive - [192.168.20.82] admin(Users)[] - Login failed using auth server SteelBelted (Radius Server). Reason: Failed <134>Juniper: 2008-10-28 03:12:03 - ive - [192.168.20.82] wenyong(Users)[Users] - Login succeeded for wenyong/Users from 192.168.20.82. <134>Juniper: 2008-10-28 03:55:20 - ive - [192.168.20.82] wenyong(Users)[Users] - Network Connect: Session ended for user with IP 172.16.3.240 <134>Juniper: 2008-10-28 03:05:25 - ive - [172.16.3.150] admin(Admin Users)[] - Primary authentication successful for admin/Administrators from 172.16.3.150 <134>Juniper: 2008-10-28 05:33:02 - ive - [172.16.3.150] admin(Admin Users)[] - Primary authentication failed for admin/Administrators from 172.16.3.150
Settings for Access Credentials
SNMP Access Credentials for All Devices
Set these Access Method Definition values to allow FortiSIEM to communicate with your device over SNMP. Set the Name and Community String.
Setting | Value |
---|---|
Name | <set name> |
Device Type | Generic |
Access Protocol | SNMP |
Community String | <your own> |