Need: Link each VPN session to the authenticated user and their assigned IP, so network traffic logs (source/destination IP, ports/services, requests) can be traced to a specific person at any point in time.
Why: VPN IPs are dynamic and shared, so today's logs show addresses rather than people. This slows investigations and audits.
Requirements:
- Log username, assigned VPN IP, public source IP, device, and connect/disconnect timestamps for every session.
- Allow lookups by IP and time that return the user who held that IP, through both the UI and an API.
- Export session events to our SIEM so they can be correlated with firewall and proxy logs.
- Restrict access to authorized roles, audit every lookup, and apply retention periods that comply with GDPR.
Need: Link each VPN session to the authenticated user and their assigned IP, so network traffic logs (source/destination IP, ports/services, requests) can be traced to a specific person at any point in time.
Why: VPN IPs are dynamic and shared, so today's logs show addresses rather than people. This slows investigations and audits.
Requirements: