networking-forum.com
Community BlogCommunity Wiki * Register  * Search  * Login
View unanswered postsView active topics

All times are UTC - 6 hours [ DST ]



Post new topic Reply to topic  [ 5 posts ] 
Author Message
PostPosted: Thu May 20, 2010 5:42 am 
Offline
New Member
New Member

Joined: Thu May 20, 2010 5:35 am
Posts: 2
Certs: Street Fighter, Lovemaking.
Hi guys,

I'm using a cisco ASA 5505 as my company firewall and I'd like to find out the IP address of the computer(s) using up the most upload bandwidth at any given time. How can I do this? I tried magic spells but they didn't work.

Thanks for reading this! I hope it's not too stupid a question.


Top
 Profile  
 
PostPosted: Thu May 20, 2010 10:18 am 
Offline
Post Whore
Post Whore
User avatar

Joined: Fri Apr 25, 2008 2:16 pm
Posts: 1361
Location: Jacksonville, FL
Certs: CCNP, CCNA:Sec, MCSE
Its not a dumb question at all. The ASDM can show you this, but its rather basic (on the main ASDM page, click on the 'Firewall Dashboard', and you should see a 'Top Usage Status' box on the right, but you may have to enable some options to get it to start showing data; keep in mind that enabling this feature uses a LOT of RAM on the ASA, so make sure you aren't running low before you start)

Image

_________________
"A problem well stated is a problem half solved". (Charles Kettering)


Top
 Profile  
 
PostPosted: Thu May 20, 2010 10:47 am 
Offline
New Member
New Member

Joined: Thu May 20, 2010 5:35 am
Posts: 2
Certs: Street Fighter, Lovemaking.
Thanks for the prompt answer.

I already know about the dashboard and the pie chart but the information is not detailed enough (as in amount of kbps per IP) or, most importantly, timely enough (only last hour average) and it includes IPs outside our network as well. I've included a screencap so you can see what I mean. Our network is all 192.168 obviously yet I find a lot of external IPs on there.

I want something close to real time, last minute would be fine for example.


Attachments:
Screen shot 2010-05-20 at 4.35.53 PM.png
Screen shot 2010-05-20 at 4.35.53 PM.png [ 74.09 KiB | Viewed 1187 times ]
Top
 Profile  
 
PostPosted: Sat May 22, 2010 9:20 pm 
Offline
Post Whore
Post Whore

Joined: Sat Jun 07, 2008 11:06 am
Posts: 2553
Location: Grand Rapids, MI
Certs: CCNP, CCDP
I can't speak to the ASA.

You could use ntop or something similar to capture the traffic off a mirrored port on the switch. It could also collect netflow data if you don't want to mirror a port, but you'll need a netflow capable device (I don't know if the ASA does this).

On a router, you could enable nbar protocol-discovery, and then show the top-talkers. Again, I don't know if the ASA has this.

You could use cacti or a similar tool to monitor switchport usage, find out which switchport has the utilization, and then trace it down from there.


Top
 Profile  
 
PostPosted: Sat May 22, 2010 9:26 pm 
Offline
Moderator
Moderator
User avatar

Joined: Mon Apr 07, 2008 10:38 am
Posts: 9390
Location: Orlando, FL
Certs: CCNP RS, CCNP DC, CCDP, CCIP
ASAs do NetFlow. Kiwi makes a free collector, I believe.

_________________
http://blog.alwaysthenetwork.com


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 5 posts ] 

All times are UTC - 6 hours [ DST ]


Who is online

Users browsing this forum: Bing [Bot] and 11 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB® Forum Software © phpBB Group