Configuration on ISA Server
-
Open ISA Management Console

-
Under the Monitoring node, click on
Logging

-
We
will create a report with the following filters
a.
Logging Last 30 Days
b. Action Equals Initiated VPN Connection
-
Click on Edit Filter, to start editing and
adding our filters.
-
Click on Log Time, then under the Condition
drop down list, choose Last 30 Days, and click
on Update

-
Click on Action,
then under the
Condition drop down list, choose Equals, and
under the Value drop down list choose
Initiated VPN Connection and click on Update

-
The
Filter will look like :

-
Click on the Start Query,
the
Query will run and the results will be displayed

As you can see, the user tmajdalani has established
3 PPTP VPN connections during the last 30 days
-
Now,
to copy the results to Excel, on the Right Side
Pane, under Tasks, click on Copy All
Result to Clipboard

-
Now
open Microsoft Excel , and paste the result.
Ok we knew how to log who established a VPN
Connection into our Network, but what if I want to
know in details what these VPN users accessed to ?
-
Of course, to Allow VPN Users to access resources
inside your LAN , you will need to create an Allow
rule as shown:

-
Create
the following Filters:

Where the value VPN Inbound Access is
the access rule that we mentioned in the previous
step.
-
Now run the Query and check what your VPN
Users have been doing all these 30 days :)
Summary
In this article, we learned how to log all the
VPN Connections established into our Network through ISA
Server. Now we know who , when and to what resources your VPN users accessed.
Related Links
Creating Detailed Reports Using ISA Server 2006 & Excel