Pattern 21 : IPSec VPN Activity

Classification

Rule Name

Rule Type

Common Event

Classification

Pattern 21 : IPSec VPN Activity

Base Rule

VPN Traffic

Network Traffic

ASA-3-713133 : PFS Group And DH Group Mismatch

Sub Rule

IPSec Proxy Mismatch

Warning

ASA-3-713194 : IPSec Delete Message Sent

Sub Rule

IPSec Delete Message Sent

Warning

Mapping with LogRhythm Schema  

Device Key in Log Message

LogRhythm Schema

Data Type

N/A

<vmid>

Number

N/A

<sip>

Number

N/A

<login>

Text/String

N/A

<group>

Text/String

N/A

<tag1>

Text/String