network logon RRS feed

  • Question

  • Hi all,

    I have a ext network that is protected by isa firewalls. We have enabled vpn on this ext network to allow my support staff to remote in for necessary support. On the security log i can see usernames of my colleagues logging on/off the domain under events 538 and 540. However when i check the firewall log of isa using the msdetotext tool i could not see any vpn connection during the time when the events for 538/540 were logged in security log, in face no vpn connections for that whole day. VPN is the only way we can access that external network. My question is when i see events 538 and 540 in security log, does it mean that there is really logging on and off process by user accounts taking place? If yes, my ext network may be hacked. Pls advise. Thks in advance.

    Monday, July 26, 2010 4:58 PM