• February 24, 2025, 03:55:08 AM
  • Welcome, Guest
Please login or register.

Login with username, password and session length
Advanced search  

News:

This Forum Beta is ONLY for registered owners of D-Link products in the USA for which we have created boards at this time.

Author Topic: Web Access Logging - How?  (Read 22783 times)

Zing Pow

  • Level 1 Member
  • *
  • Posts: 3
Web Access Logging - How?
« on: November 30, 2011, 01:23:06 AM »

Is it possible to get both allowed and blocked web access logging?  I'm using the 2.06NA firmware and no matter how I configure the router, I just can't get it to work, so either I'm missing something or the firmware has a defect, I hope its me, but I fear its a defect.

Thanks
Logged

FurryNutz

  • Poweruser
  •   ▲
    ▲ ▲
  • *****
  • Posts: 49923
  • D-Link Global Forum Moderator
    • Router Troubleshooting
Re: Web Access Logging - How?
« Reply #1 on: November 30, 2011, 07:19:33 AM »

Logging? you referring to having the router show when certain sites are being accessed and blocked?
Logged
Cable: 1Gb/50Mb>NetGear CM1200>DIR-882>HP 24pt Gb Switch. COVR-1202/2202/3902,DIR-2660/80,3xDGL-4500s,DIR-LX1870,857,835,827,815,890L,880L,868L,836L,810L,685,657,3x655s,645,628,601,DNR-202L,DNS-345,DCS-933L,936L,960L and 8000LH.

Zing Pow

  • Level 1 Member
  • *
  • Posts: 3
Re: Web Access Logging - How?
« Reply #2 on: November 30, 2011, 11:10:37 AM »

Let me go through a detailed step by step of my configuration with some comments and then hopefully someone can point out what I've missed as certainly no web access information is showing up in the syslog output or the logging page.

First my objective, to recieve web access information via syslog for all sites visited and an indication of attempts to visit blocked sites.

I am receiving information from the router via syslog so that is working (just not receiving the information I want).





Web Filter Setup (note I want to list sites to block here as my general policy is to let people go where they want and if it becomes a problem we block access to selected sites)



I then setup a Policy

Name


Want it on all the time


Select Other Machines as we want this policy to apply to all systems on the network


We want to block our selected sites


Apparently there is not Step 5, but again we are asked about Web Access Logging which we want so its Enabled


and the resulting policy is created, enabled etc.



Now when we visit the blocked site we the browser displays that the site is blocked (good)



However no indiciation in the syslog or logging screen about the blocked access, in fact there isn't any Web Access information in the logging screen or syslog.



So what have I missed configured or is this a defect in the firmware?

Thanks
Logged

FurryNutz

  • Poweruser
  •   ▲
    ▲ ▲
  • *****
  • Posts: 49923
  • D-Link Global Forum Moderator
    • Router Troubleshooting
Re: Web Access Logging - How?
« Reply #3 on: November 30, 2011, 11:39:40 AM »

Is possible that the FW doesn't support or report any return information back on logging access to blocked sites as these are generally home user routers that might not incorporate a lot of advanced diagnostic features as say a business class router might have.

I'll have a check when I get home and see if I get the same results.
Logged
Cable: 1Gb/50Mb>NetGear CM1200>DIR-882>HP 24pt Gb Switch. COVR-1202/2202/3902,DIR-2660/80,3xDGL-4500s,DIR-LX1870,857,835,827,815,890L,880L,868L,836L,810L,685,657,3x655s,645,628,601,DNR-202L,DNS-345,DCS-933L,936L,960L and 8000LH.

FurryNutz

  • Poweruser
  •   ▲
    ▲ ▲
  • *****
  • Posts: 49923
  • D-Link Global Forum Moderator
    • Router Troubleshooting
Re: Web Access Logging - How?
« Reply #4 on: November 30, 2011, 04:13:38 PM »

I got this from my DIR-655  B1 v2.00 info Nov 30 17:12:00  test.com/ blocked for #.#.57.3  

Testing out my 825:
Rev. B1 FW-v2.05NA
Nov 30 17:57:09 test.com/favicon.ico accessed from ##.57.3
Changed to Deny Access
Nov 30 17:58:26 test.com/ blocked for #.#.57.3
« Last Edit: November 30, 2011, 07:40:06 PM by FurryNutz »
Logged
Cable: 1Gb/50Mb>NetGear CM1200>DIR-882>HP 24pt Gb Switch. COVR-1202/2202/3902,DIR-2660/80,3xDGL-4500s,DIR-LX1870,857,835,827,815,890L,880L,868L,836L,810L,685,657,3x655s,645,628,601,DNR-202L,DNS-345,DCS-933L,936L,960L and 8000LH.

Zing Pow

  • Level 1 Member
  • *
  • Posts: 3
Re: Web Access Logging - How?
« Reply #5 on: November 30, 2011, 06:26:55 PM »

Perhaps I need to roll back the firmware version then as perhaps the 2.06NA firmware has a problem?

When you change to 'Deny Access' do you still get notification of permitted web access?  If not is there a way you can get your router to log both permitted and denied?

If I can the policy to Log Web Access Only (step 4), then I get logging of web access:

<13>kernel: Web Access Logs: www.dslreports.com accessed from 192.168.0.101 (00:19:d1:90:03:8b)

but then it won't deny the sites I entered.

How many policies are you running?  If I create a policy for each machine where I setup 'Block Some Access' then I can get both access and denied logs,

<14>urlblock[20595]: test.com blocked for 192.168.0.101

but if a new machine hooked into the network they would be able to access sites I would want blocked by default.  So in short while I might be able to fudge something together which sort of works, the 2.06NA firmware is IMHO broken when it comes to logging web access.  Certainly if someone from D-Link wants to talk to me, I would be happy to work with them to get this working correctly.

Blake
Logged

FurryNutz

  • Poweruser
  •   ▲
    ▲ ▲
  • *****
  • Posts: 49923
  • D-Link Global Forum Moderator
    • Router Troubleshooting
Re: Web Access Logging - How?
« Reply #6 on: November 30, 2011, 07:31:33 PM »

I think Web access is set for either Deny or Allow and you can't do both at the same time.

I can load up 2.06 tomorrow and test to see if I can reproduce this using that version. I presume that I might now however will see.

Are there certain users on your network that your trying to manage?
Also have you set up a schedule for inclusion to the management?

I only added one policy to test however you should be able to any many. Just need to figure out what sites you want to Deny vs allow.
Logged
Cable: 1Gb/50Mb>NetGear CM1200>DIR-882>HP 24pt Gb Switch. COVR-1202/2202/3902,DIR-2660/80,3xDGL-4500s,DIR-LX1870,857,835,827,815,890L,880L,868L,836L,810L,685,657,3x655s,645,628,601,DNR-202L,DNS-345,DCS-933L,936L,960L and 8000LH.