Re: How to trace all the users accessing Internet.

  • From: "cismic" <cismic@xxxxxxx>
  • To: "[ISAserver.org Discussion List]" <isalist@xxxxxxxxxxxxx>
  • Date: Mon, 10 May 2004 06:59:03 -0700

How to trace all the users accessing Internet.Hi Athif,

When your users are accessing the outside world of the internet the web proxy 
logs won't show
"DOMAIN\USERNAME" in the logs unless you specifiy to use authenticated 
connections.  
So, what that measn is that you can setup client side rules based on groups or 
individual
users rather then looking in the proxy logs.  As a general rule, I like adding 
my own agent
settings to the system registry where, explorer is installed that includes 
things such as machine name
and user name. That way when I look in the ISA logs I can see what machine and 
what user accessed
the web. This allows me to keep the anonymous settings etc.  

I guess there are several ways and methods to setup the usage of ISA and 
polices and I only mention
the method that I use.

Thank you,
Joseph
  ----- Original Message ----- 
  From: mathif@xxxxxxxxxxxxxxx 
  To: [ISAserver.org Discussion List] 
  Sent: Sunday, May 09, 2004 7:28 AM
  Subject: [isalist] How to trace all the users accessing Internet.


  http://www.ISAserver.org

  Hi Folks, 
  I actually need to know all the users accessing Internet thru ISA to define 
the access policies as the currently therez no access policy.

  To my knowledge, the best method can be thru the Web Proxy Logs. But the log 
file is more that 1 GB and it will be difficult to drill down and trace all 
those users. Is there a way like any script which can take out all those 
"DOMAIN\username" from the logfiles or is there any other short cut method for 
this??!

  Thanks in Advance, 
  Athif...! 



  ----------------------------------------------------- 
  This email and any files transmitted with it are confidential and intended 
solely for the use of the individual or entity to whom/which they are 
addressed. If you have received this email in error please notify the system 
manager at the following email address: sadmin@xxxxxxxxxxxxxxx 
<mailto:sadmin@xxxxxxxxxxxxxxx>. Please note that any views or opinions 
presented in this email are solely those of the author and do not necessarily 
represent those of Al Faisaliah Group. Internet communications cannot be 
guaranteed to be secure or error-free as information could be intercepted, 
corrupted, lost, arrive late or contain viruses. The sender therefore does not 
accept liability for any errors or omissions in the context of this message, 
which arise as a result of Internet transmission.  Finally, the recipient 
should check this email and any attachments for the presence of viruses. Al 
Faisaliah Group accepts no liability for any damage caused by any virus 
transmitted by this email. 

  ----------------------------------------------------- 


  ------------------------------------------------------
  List Archives: http://www.webelists.com/cgi/lyris.pl?enter=isalist
  ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp
  ISA Server FAQ: http://www.isaserver.org/pages/larticle.asp?type=FAQ
  ------------------------------------------------------
  Other Internet Software Marketing Sites:
  Leading Network Software Directory: http://www.serverfiles.com
  No.1 Exchange Server Resource Site: http://www.msexchange.org
  Windows Security Resource Site: http://www.windowsecurity.com/
  Network Security Library: http://www.secinf.net/
  Windows 2000/NT Fax Solutions: http://www.ntfaxfaq.com
  ------------------------------------------------------
  You are currently subscribed to this ISAserver.org Discussion List as: 
cismic@xxxxxxx
  To unsubscribe send a blank email to $subst('Email.Unsub') 

Other related posts: