LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 05-30-2010, 11:03 AM   #1
qwertyjjj
Senior Member
 
Registered: Jul 2009
Location: UK
Distribution: Cent OS5 with Plesk
Posts: 1,013

Rep: Reputation: 30
track VPN requests


I have a proxy server with all relevant logs compiled by SARG.
I also have a VPN but am not sure how to go about creating logs of http access requests or any other requests from openVPN - any ideas?
Also, would the overhead created be too much?
 
Old 06-01-2010, 04:31 AM   #2
huwnet
Member
 
Registered: Jan 2006
Location: England
Distribution: Arch
Posts: 119

Rep: Reputation: Disabled
It would be fairly intensive to monitor http requests on a VPN as you'd have to examine each packet coming through. Have you considered installing Squid (an http proxy) and then setting it up as a transparent proxy so that all http requests pass through it? You could then use the various logs for squid to do what you want
 
Old 06-01-2010, 04:40 AM   #3
linuxgurusa
Member
 
Registered: Mar 2008
Location: Namibia, Swakopmund
Distribution: Redhat, Fedora, Centos, ClearOS, Mandrake
Posts: 151

Rep: Reputation: 29
Quote:
Originally Posted by huwnet View Post
It would be fairly intensive to monitor http requests on a VPN as you'd have to examine each packet coming through. Have you considered installing Squid (an http proxy) and then setting it up as a transparent proxy so that all http requests pass through it? You could then use the various logs for squid to do what you want
+1 yes, by doing this you will see all web browsing.
You just need to make sure that the IP's on the VPN traffic stay the same so you can track back the users?
 
Old 06-01-2010, 06:07 AM   #4
huwnet
Member
 
Registered: Jan 2006
Location: England
Distribution: Arch
Posts: 119

Rep: Reputation: Disabled
Quote:
You just need to make sure that the IP's on the VPN traffic stay the same so you can track back the users?
I hadn't thought of this, but you'd certainly need to do this. Alternatively if your VPN is using RADIUS authentication/accounting you may be able to use RADIUS with squid too
 
Old 06-01-2010, 07:52 AM   #5
qwertyjjj
Senior Member
 
Registered: Jul 2009
Location: UK
Distribution: Cent OS5 with Plesk
Posts: 1,013

Original Poster
Rep: Reputation: 30
Quote:
Originally Posted by linuxgurusa View Post
+1 yes, by doing this you will see all web browsing.
You just need to make sure that the IP's on the VPN traffic stay the same so you can track back the users?
Each VPN client has a different IP although they are of the same 17.x.x.x variety.
At the moment my squid uses NCSA auth so not sure how I could apply a logon for the VPN?
 
Old 06-01-2010, 07:57 AM   #6
linuxgurusa
Member
 
Registered: Mar 2008
Location: Namibia, Swakopmund
Distribution: Redhat, Fedora, Centos, ClearOS, Mandrake
Posts: 151

Rep: Reputation: 29
Quote:
Originally Posted by qwertyjjj View Post
Each VPN client has a different IP although they are of the same 17.x.x.x variety.
At the moment my squid uses NCSA auth so not sure how I could apply a logon for the VPN?
Howdy Bud
If your users are authenticating, then you should see the usernames when you run a browsing report, whether they are in or outside the VPN, so problem solved there then !
 
Old 06-01-2010, 08:17 AM   #7
qwertyjjj
Senior Member
 
Registered: Jul 2009
Location: UK
Distribution: Cent OS5 with Plesk
Posts: 1,013

Original Poster
Rep: Reputation: 30
Quote:
Originally Posted by linuxgurusa View Post
Howdy Bud
If your users are authenticating, then you should see the usernames when you run a browsing report, whether they are in or outside the VPN, so problem solved there then !
Well, they authenticate through using a cert.
But they are not given a proxy auth, I suppose I could ask them to but the proxy is not set up for transparency and can't be because of the separate proxy users using ncsa.

Also, I guess opening up the VPN to all traffic means it COULD be used for something that I cannot log
 
Old 06-10-2010, 06:01 PM   #8
qwertyjjj
Senior Member
 
Registered: Jul 2009
Location: UK
Distribution: Cent OS5 with Plesk
Posts: 1,013

Original Poster
Rep: Reputation: 30
Any ideas?
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Dynamic IP VPN between IpSec(OpenBSD) and Linux VPN software Peter_APIIT Linux - Server 2 04-09-2008 05:08 AM
Configure Linux VPN Server for a Windows VPN Client xbaez Linux - Networking 4 04-28-2006 03:29 PM
apache track incoming, outgoing requests real-time dtra Linux - Networking 1 07-18-2005 07:19 AM
How do i connect Ciscos VPN client to Checkpoint VPN server Klas Linux - Networking 1 11-29-2003 08:00 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 08:11 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration