All other Cisco networking related discussions.
gozulin
New Member
Posts:
2
Joined:
Thu May 20, 2010 5:35 am
Certs:
Street Fighter, Lovemaking.

Who is hogging my upload bandwidth? (ASA 5505 , ASDM)

Thu May 20, 2010 5:42 am

Hi guys,

I'm using a cisco ASA 5505 as my company firewall and I'd like to find out the IP address of the computer(s) using up the most upload bandwidth at any given time. How can I do this? I tried magic spells but they didn't work.

Thanks for reading this! I hope it's not too stupid a question.

User avatar
Dinger
Post Whore
Posts:
1397
Joined:
Fri Apr 25, 2008 2:16 pm
Certs:
CCNP, CCNA:Sec, MCSE

Re: Who is hogging my upload bandwidth? (ASA 5505 , ASDM)

Thu May 20, 2010 10:18 am

Its not a dumb question at all. The ASDM can show you this, but its rather basic (on the main ASDM page, click on the 'Firewall Dashboard', and you should see a 'Top Usage Status' box on the right, but you may have to enable some options to get it to start showing data; keep in mind that enabling this feature uses a LOT of RAM on the ASA, so make sure you aren't running low before you start)

Image
"A problem well stated is a problem half solved". (Charles Kettering)

gozulin
New Member
Posts:
2
Joined:
Thu May 20, 2010 5:35 am
Certs:
Street Fighter, Lovemaking.

Re: Who is hogging my upload bandwidth? (ASA 5505 , ASDM)

Thu May 20, 2010 10:47 am

Thanks for the prompt answer.

I already know about the dashboard and the pie chart but the information is not detailed enough (as in amount of kbps per IP) or, most importantly, timely enough (only last hour average) and it includes IPs outside our network as well. I've included a screencap so you can see what I mean. Our network is all 192.168 obviously yet I find a lot of external IPs on there.

I want something close to real time, last minute would be fine for example.
Attachments
Screen shot 2010-05-20 at 4.35.53 PM.png
Screen shot 2010-05-20 at 4.35.53 PM.png (74.09 KiB) Viewed 1531 times

Fred
Post Whore
Posts:
2566
Joined:
Sat Jun 07, 2008 11:06 am
Certs:
CCNP, CCDP

Re: Who is hogging my upload bandwidth? (ASA 5505 , ASDM)

Sat May 22, 2010 9:20 pm

I can't speak to the ASA.

You could use ntop or something similar to capture the traffic off a mirrored port on the switch. It could also collect netflow data if you don't want to mirror a port, but you'll need a netflow capable device (I don't know if the ASA does this).

On a router, you could enable nbar protocol-discovery, and then show the top-talkers. Again, I don't know if the ASA has this.

You could use cacti or a similar tool to monitor switchport usage, find out which switchport has the utilization, and then trace it down from there.

User avatar
Vito_Corleone
Moderator
Posts:
9847
Joined:
Mon Apr 07, 2008 10:38 am
Certs:
CCNP RS, CCNP DC, CCDP, CCIP

Re: Who is hogging my upload bandwidth? (ASA 5505 , ASDM)

Sat May 22, 2010 9:26 pm

ASAs do NetFlow. Kiwi makes a free collector, I believe.
http://blog.alwaysthenetwork.com

'

Return to Cisco General

Who is online

Users browsing this forum: No registered users and 20 guests