Mail when SSL failed login

I have a Firebox M290 and Dimension server.
SSL VPN is configured for my users.
The Dimension is configured to send email.

How can I configure so my dimension sends an mail when there is a failed login attempt via SSL VPN?
And also when there is a successful login.

I cannot for my life find where and how to do that. :/

Comments

  • The general process:
    In WSM Firebox System Manager, you can select an already received log message ID, and set for notification when that ID happens again.
    See the following:

    Enable Notification for Specific Messages
    www.watchguard.com/help/docs/help-center/en-US/Content/en-US/Fireware/fsm/enable_notification_messages_wsm.html

    You can look up Log message IDs in the WatchGuard Log Catalog:
    https://www.watchguard.com/help/docs/fireware/12/en-US/log_catalog/12_11_Log-Catalog.pdf

    Note that the Log message IDs in the WatchGuard Log Catalog omit the dash from the middle of the log message ID as shown in Traffic Monitor.

    A quick search of the WatchGuard Log Catalog shows:
    25000000 VPN / SSLVPN User login
    25000001 VPN / SSLVPN User log off

    I'm sure you can find the log message for a failed login from Traffic Monitor, but it may be also used for other types of failed logins.
    The WatchGuard Log Catalog will show the uses for the log message ID that you find.

  • @Bruce_Briggs said:
    The general process:
    In WSM Firebox System Manager, you can select an already received log message ID, and set for notification when that ID happens again.
    See the following:

    Enable Notification for Specific Messages
    www.watchguard.com/help/docs/help-center/en-US/Content/en-US/Fireware/fsm/enable_notification_messages_wsm.html

    You can look up Log message IDs in the WatchGuard Log Catalog:
    https://www.watchguard.com/help/docs/fireware/12/en-US/log_catalog/12_11_Log-Catalog.pdf

    Note that the Log message IDs in the WatchGuard Log Catalog omit the dash from the middle of the log message ID as shown in Traffic Monitor.

    A quick search of the WatchGuard Log Catalog shows:
    25000000 VPN / SSLVPN User login
    25000001 VPN / SSLVPN User log off

    I'm sure you can find the log message for a failed login from Traffic Monitor, but it may be also used for other types of failed logins.
    The WatchGuard Log Catalog will show the uses for the log message ID that you find.

    THANK you so much. :)
    There it was.
    You saved my day.

Sign In to comment.