Monitoring/correlating traffic to VPN sessions
Posted: Wed Mar 06, 2019 9:58 pm
Hi all,
I have a problem with two (interrelated) components of our network, and one of those is OpenVPN. I'm not sure if the problem can be solved by fixing one part, or both.
- We have a number of users who work remotely and connect to our internal LAN using OpenVPN. Pretty standard.
- We also have an IDS appliance inside the network perimeter, that watches for unusual network activity. Also pretty standard.
The problem I'm running into is that, within the perimeter of the LAN, any traffic generated by VPN users appears to be coming from the OpenVPN server itself. That itself isn't an issue since I'm still getting alerted to suspicious activity, and I know the VPN server isn't the true source of the traffic - the problem is that the OVPN logs don't contain any information I can use to trace the activity back to a specific remote user.
I was trying to figure out if increasing the logfile verbosity might help, but the documentation doesn't clarify what the different logging levels actually do.
Any suggestions?
I have a problem with two (interrelated) components of our network, and one of those is OpenVPN. I'm not sure if the problem can be solved by fixing one part, or both.
- We have a number of users who work remotely and connect to our internal LAN using OpenVPN. Pretty standard.
- We also have an IDS appliance inside the network perimeter, that watches for unusual network activity. Also pretty standard.
The problem I'm running into is that, within the perimeter of the LAN, any traffic generated by VPN users appears to be coming from the OpenVPN server itself. That itself isn't an issue since I'm still getting alerted to suspicious activity, and I know the VPN server isn't the true source of the traffic - the problem is that the OVPN logs don't contain any information I can use to trace the activity back to a specific remote user.
I was trying to figure out if increasing the logfile verbosity might help, but the documentation doesn't clarify what the different logging levels actually do.
Any suggestions?