FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
candawi
Staff
Staff
Article Id 317037
Description

 

This article describes a way to create a report that shows the date and time of connected and disconnected SSL VPN users from FortiGate logs.

 

Scope

 

FortiGate with SSL VPN.

 

Solution

 

  1. Create a report for the date and time of users connected through SSL VPN by downloading the logs from VPN events. Refer to this guide for obtaining the logs: Technical Tip: View historic SSL VPN user connectivity logs.

  2. Filter with messages: SSL tunnel established & SSL tunnel shutdown.

Picture 1.png

  1. Download the log.

    Picture 2.png

     

     

  2. Open Excel and create a new spreadsheet. 

     

  3. Select the Data tab.

     

  4. Select From Text/CSV.

     

  5. Since the log is in .log instead of .txt file format, select All Files.

    Picture 4.png

     

     

  6. Select the log file and select Import.

     

  7. Since space is what separates each field in the log file, select Space under Delimiter.

    Picture 5.png

     

  8. Select Load.

     

  9. Proceed in customizing the report and removing fields that are not necessary. 

    Picture 6.png

     

     

Additional Information:

  • A FortiGate local report is not customizable and limited only to bandwidth reports for VPN usage.
  • Consider using FortiAnalyzer to generate a VPN report. Refer to VPN report update 7.2.1 and consult local sales if the requirement can be done by customizing a report in FortiAnalyzer.

 

Related articles:

Technical Tip: Local Reports

Technical Tip: How to build a custom report on FortiAnalyzer using Chart Builder