Administrator's Guide - Kerio Software Archive

Administrator's Guide - Kerio Software Archive Administrator's Guide - Kerio Software Archive

download.kerio.com
from download.kerio.com More from this publisher
30.01.2015 Views

Logs 4. Failed user authentication log records Message format: Authentication: : Client: : • — The Kerio Control service to which the user attempted to authenticate (Admin = administration using Administration Console, WebAdmin = web administration interface, WebAdmin SSL = secure web administration interface, Proxy = proxy server user authentication) • — IP address of the computer from which the user attempted to authenticate • — reason of the authentication failure (nonexistent user / wrong password) Note: For detailed information on user quotas, refer to chapters 16.1 and 11.1. 5. Information about the start and shutdown of the Kerio Control Engine a) Engine Startup: [17/Dec/2008 12:11:33] Engine: Startup. b) Engine Shutdown: [17/Dec/2008 12:22:43] Engine: Shutdown. 22.12 Sslvpn Log In this log, operations performed in the Clientless SSL-VPN interface are recorded. Each log line provides information about an operation type, name of the user who performed it and file associated with the operation. Example: [17/Mar/2008 08:01:51] Copy File: User: jsmith@company.com File: ’\\server\data\www\index.html’ The Clientless SSL-VPN interface and the corresponding log is available in Kerio Control for Windows only. 22.13 Warning Log The Warning log displays warning messages about errors of little significance. Warnings can display for example reports about invalid user login (invalid username or password), error in communication of the server and Web administration interface, etc. 304

22.13 Warning Log Events causing display of warning messages in this log do not greatly affect Kerio Control’s operation. They can, however, indicate certain (or possible) problems. The Warning log can help if for example a user is complaining that certain services are not working. Each warning message is identified by its numerical code (code xxx:). The following warning categories are defined: • 1000-1999 — system warnings (e.g. an application found that is known as conflicting) • 2000-2999 — Kerio Control configuration issues (invalid values retrieved from the configuration file) • 3000-3999 — warning from operations of Kerio Control Engine (e.g. DHCP, DNS, anti-virus check, user authentication, etc.) • 4000-4999 — license warnings (subscription expiration, forthcoming expiration of Kerio Control’s license, Kerio Web Filter license, or the anti-virus license) Note: License expiration is considered to be an error and it is logged into the Error log. • 5000-5099 — Bandwidth Limiter warnings • 5100-5199 — Kerio Web Filter warnings • 5200-5299 — crashdumps Examples of Warning logs: [15/Apr/2008 15:00:51] (3004) Authentication subsystem warning: Kerberos 5 auth: user james@company.com not authenticated [15/Apr/2008 15:00:51] (3004) Authentication subsystem warning: Invalid password for user admin [16/Apr/2008 10:53:20] (3004) Authentication subsystem warning: User jflyaway doesn’t exist • The first log informs that authentication of user jsmith by the Kerberos system in the company.com domain failed • The second log informs on a failed authentication attempt by user admin (invalid password) • The third log informs on an authentication attempt by a user which does not exist (johnblue) 305

Logs<br />

4. Failed user authentication log records<br />

Message format:<br />

Authentication: : Client: : <br />

• — The <strong>Kerio</strong> Control service to which the user attempted to<br />

authenticate (Admin = administration using Administration Console, WebAdmin<br />

= web administration interface, WebAdmin SSL = secure web administration<br />

interface, Proxy = proxy server user authentication)<br />

• — IP address of the computer from which the user attempted to<br />

authenticate<br />

• — reason of the authentication failure (nonexistent user / wrong<br />

password)<br />

Note: For detailed information on user quotas, refer to chapters 16.1 and 11.1.<br />

5. Information about the start and shutdown of the <strong>Kerio</strong> Control Engine<br />

a) Engine Startup:<br />

[17/Dec/2008 12:11:33] Engine:<br />

Startup.<br />

b) Engine Shutdown:<br />

[17/Dec/2008 12:22:43] Engine:<br />

Shutdown.<br />

22.12 Sslvpn Log<br />

In this log, operations performed in the Clientless SSL-VPN interface are recorded. Each log<br />

line provides information about an operation type, name of the user who performed it and file<br />

associated with the operation.<br />

Example:<br />

[17/Mar/2008 08:01:51] Copy File: User: jsmith@company.com<br />

File:<br />

’\\server\data\www\index.html’<br />

The Clientless SSL-VPN interface and the corresponding log is available in <strong>Kerio</strong> Control for<br />

Windows only.<br />

22.13 Warning Log<br />

The Warning log displays warning messages about errors of little significance. Warnings can<br />

display for example reports about invalid user login (invalid username or password), error in<br />

communication of the server and Web administration interface, etc.<br />

304

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!