This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Log file for Failed Authentication Attempts?

I'm transitioning over from Microsoft TMG and one thing I can do in the TMG is look at any and all traffic coming from a host and see if it's authenticated or not.  It looks like the UTM only logs traffic after it's been authenticated (if it's required).  Is there anyway to have it log traffic when the authentication fails?  The "User Authentication Daemon" only shows authentication of the UTM WebAdmin or Portal itself, not against web filtering requests.  Is there another log I'm missing?  Thx!


This thread was automatically locked due to age.
Parents
  • You're right.  To get the details of which IPs/FQDNs need an Exception for Authentication, make an Exception for Auth for everything from that workstation - maybe that's what you meant.

    Cheers - Bob
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply
  • You're right.  To get the details of which IPs/FQDNs need an Exception for Authentication, make an Exception for Auth for everything from that workstation - maybe that's what you meant.

    Cheers - Bob
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Children
No Data