Skip to content

VPN User-to-IP Attribution for Network Log Correlation #3763

Description

@jacobdefguard

Need: Link each VPN session to the authenticated user and their assigned IP, so network traffic logs (source/destination IP, ports/services, requests) can be traced to a specific person at any point in time.

Why: VPN IPs are dynamic and shared, so today's logs show addresses rather than people. This slows investigations and audits.

Requirements:

  • Log username, assigned VPN IP, public source IP, device, and connect/disconnect timestamps for every session.
  • Allow lookups by IP and time that return the user who held that IP, through both the UI and an API.
  • Export session events to our SIEM so they can be correlated with firewall and proxy logs.
  • Restrict access to authorized roles, audit every lookup, and apply retention periods that comply with GDPR.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    featureNew feature or request

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions