IAM Cannot Audit The Websites That Were Accessed

|
  • 117
  • 7

Issue Description

Two users are in the same domain and the policy is the same, one user can be audited, but for another user there are many access records that cannot be audited.

Handling Process

1. Verify that the online user matching policy is correct and the audit policy is enabled.
2. The report center can see some logs, when testing to access the web pages it cannot be audited.
3. Behavior monitoring real-time view has no log, in connection monitoring has no log as well.
4. Capture the packets on the IAM LAN port, it does not contain the data of the visited website.
5. Verify that the PC does not have a dual network card, use Wireshark to capture the packets on the PC, and found out that the browser is configured with the proxy.
(Client PC172.20.42.204—>Proxy Server 172.20.20.190)

Root Cause

The browser is configured with the proxy.

Solution

If audit is required the browser proxy has to be disabled.
Faisal Posted 16 Aug 2020 10:38
  
Thank you very much for the information ...
Muhammad Bilal Lv4Posted 15 Sep 2020 00:51
  
Thanks for sharing the information
Faisal Posted 27 Oct 2020 10:56
  
Nice article ...
Faisal Posted 12 Dec 2020 08:54
  
Great info ...
Ellechar Lv4Posted 02 Feb 2021 10:27
  
Very nice infooooooooooooooooooooooooooooo
Faisal Posted 15 Mar 2021 07:55
  
Very informative …
Faisal Posted 31 May 2021 12:45
  
Nice guidance ...

I want to write a case
Doc ID: 2427
Author: Sangfor_SY
Updated: 2019-12-23 15:36
Version: