Event List Filtering on VPN Concentrator.

From: pankaj ahuja (networksecurityconsultant@gmail.com)
Date: Tue Sep 25 2007 - 10:56:31 ART


Hello All,

I have a VPN Concentrator and am trying to configure it so that an SNMP Trap
is sent to a machine for only failed authentication attempts. I do not want
to receive any more events, so what I did is under the page -

Configuration | System | Events | General

I selected the value "Use Events list" for "Events to Trap"

and under Events list I have the following values:

Auth/31, SEV(5)
Auth/9, SEV(4)

Also on the PAge - Configuration | System | Events | Classes

the settings for Class authentication is set to use Event list for traps.

But still for some reason I am receiving traps that do not meet this
criteria of Auth/31 and Auth/9.

The Software version on this VPN Concentrator is -- 4.0.4.A.

Upgrading the software is not an option right now.

Please let me know if any of you have been able to get this to filter to
exact Event list.

Thanks

Regards
Pankaj



This archive was generated by hypermail 2.1.4 : Sat Oct 06 2007 - 12:01:15 ART