networking-forum.com
Community BlogCommunity Wiki * Register  * Search  * Login
View unanswered postsView active topics

All times are UTC - 6 hours [ DST ]



Post new topic Reply to topic  [ 15 posts ] 
Author Message
PostPosted: Wed Jul 20, 2011 8:37 am 
Offline
New Member
New Member

Joined: Tue Jul 19, 2011 8:47 am
Posts: 38
Just wondering what suggestions people have in relation to monitoring traffic on their ASA, generally we have no need to but we have had instances where we've wanted to find out what server/pc is hogging bandwidth.

I've had a look around and found NTOP which utilises NetFlow (not used before) but this isn't realtime from what I can gather. More often than not we'd want to find out what's going on realtime/now, not what happened 5 mins ago.

Any thoughts?


Top
 Profile  
 
PostPosted: Wed Jul 20, 2011 9:02 am 
Offline
Post Whore
Post Whore
User avatar

Joined: Thu Apr 29, 2010 6:12 pm
Posts: 2083
Location: Texas
Certs: CCNP, CCDP, CCIP
"Real-time" is going to be hard to come by. NetFlow and SNMP are my tools of choice. Keep in mind though you can adjust the poling intervails to sub-minute rates (on some tools) but you are going to start chewing up a ton of firewall and server resources. Some tools out there will freak out and not be able to handle this. Your ASA might not like it either.

just like debug, you will get a ton of information but at a high cost.

_________________
http://blog.movingonesandzeros.net/


Top
 Profile  
 
PostPosted: Wed Jul 20, 2011 9:19 am 
Offline
CCIE #20728
CCIE #20728
User avatar

Joined: Thu Aug 09, 2007 11:22 am
Posts: 1442
Location: Frankfurt, Germany
Did something like that a few years ago with RRD and own written Perl/PHP Scripts as an on Demand Service.
We got a php Front end which let you choose which device and link to monitor and at which interval. The PHP Scripts did create the RRD Database and started the Perl Script which worked in deamon mode and just queried the SNMP Mibs within every intervall and put it into the RRD Database.

After we did not need it any more the stuff was deleted so the server and device did not have issues with resources over a long time period. The only thing I saw so far which was able to create near real time monitoring without a sky high price.

_________________
http://ccie20728.wordpress.com/


Top
 Profile  
 
PostPosted: Thu Jul 21, 2011 2:14 am 
Offline
New Member
New Member

Joined: Tue Jul 19, 2011 8:47 am
Posts: 38
Yeah I've read about the load it can have on CPU, etc. It's a shame you can't just select the Outside interface and breakdown the data/source in realtime via ASDM. Half the problem is first identifying the best place to monitor the data.


Top
 Profile  
 
PostPosted: Mon Aug 01, 2011 9:34 am 
Offline
New Member
New Member

Joined: Tue Sep 08, 2009 6:46 am
Posts: 7
Location: India
NetFlow is the best but, yes, NetFlow export from Cisco ASA is not real-time. ASA NetFlow known as NSEL (NetFlow Secure Event Logging) is based on events triggered on the ASA.

Enabling NetFlow is not going to bug your firewall. I have had many customers use NetFlow from Cisco ASA with the NetFlow monitoring product Iam a part of. I never came across an issue of CPU or memory shoot ups on the ASA due to enabling NetFlow. So, its safe. And since its the ASA, get a free version of some NetFlow software. My product's free edition can monitor 2 interfaces with all features including data storage. The product is ManageEngine NetFlow Analyzer.

Regards,
Don Thomas


Top
 Profile  
 
PostPosted: Mon Aug 01, 2011 9:56 am 
Offline
Senior Member
Senior Member
User avatar

Joined: Mon May 30, 2011 1:51 pm
Posts: 387
Location: AR, USA
Certs: ccna, ccna security, ccna voice, ccnp, ccip
the only way you are going to get "realtime" is to put in a tap or SPAN off a switch and use NTOP as the traffic flows, not as a netflow probe....

and still that has to refresh the webpage to show you "top talkers" just like if you were using a more pricey Netscout with nGenius frontend...

or tap with wireshark (tshark) or cace pilot server...

netflow, ipfix, sflow is always going to have tax the router/switch/firewall under question and have to collect and dump to the collecting station...

_________________
"With sufficient thrust, pigs fly just fine..." - RFC 1925


Top
 Profile  
 
PostPosted: Mon Aug 01, 2011 10:16 am 
Offline
Senior Member
Senior Member
User avatar

Joined: Mon May 30, 2011 1:51 pm
Posts: 387
Location: AR, USA
Certs: ccna, ccna security, ccna voice, ccnp, ccip
http://www.netoptics.com/sites/default/files/Data.pdf

_________________
"With sufficient thrust, pigs fly just fine..." - RFC 1925


Top
 Profile  
 
PostPosted: Wed Sep 28, 2011 3:13 am 
Offline
New Member
New Member
User avatar

Joined: Fri Sep 23, 2011 1:49 am
Posts: 12
Thank you very much for sharing that information, I also want to monitor real time traffic as well.


Top
 Profile  
 
PostPosted: Sun Oct 30, 2011 12:37 am 
Offline
CCIE #24973
CCIE #24973
User avatar

Joined: Fri Mar 02, 2007 5:18 am
Posts: 196
Location: Bahrain
Certs: CCNP,CCSP,CCIE (R&S)#24973
you can setup a "Cacti" along with Realtime plugin.

_________________
"Nothing Is Limited, Except Our Understanding To The Universe"


Top
 Profile  
 
PostPosted: Fri Nov 04, 2011 9:34 pm 
Offline
Post Whore
Post Whore

Joined: Sat Jun 07, 2008 11:06 am
Posts: 2553
Location: Grand Rapids, MI
Certs: CCNP, CCDP
Remember that at any given moment, a link is either 100% utilized, or 0% utilized, since it's a digital signal.


Top
 Profile  
 
PostPosted: Wed Nov 23, 2011 6:29 am 
Offline
New Member
New Member

Joined: Tue Jul 19, 2011 8:47 am
Posts: 38
Anybody using SNMP to monitor their ASA and are there any security implications to think about?


Top
 Profile  
 
PostPosted: Wed Nov 23, 2011 9:21 am 
Offline
Post Whore
Post Whore
User avatar

Joined: Tue Aug 21, 2007 2:15 pm
Posts: 8303
Location: Frederick MD
Certs: Instanity
sparky wrote:
Anybody using SNMP to monitor their ASA and are there any security implications to think about?



all depends on what version of SNMP you are talking about.

_________________
"If you're good at anticipating the human mind. It leaves nothing to chance."
-Jigsaw


Top
 Profile  
 
PostPosted: Sat Feb 11, 2012 2:25 am 
Offline
Member
Member

Joined: Sat Mar 26, 2011 10:42 pm
Posts: 133
bakergarry wrote:
the only way you are going to get "realtime" is to put in a tap or SPAN off a switch and use NTOP as the traffic flows, not as a netflow probe....


Top
 Profile  
 
PostPosted: Thu Mar 22, 2012 4:47 am 
Offline
Junior Member
Junior Member

Joined: Tue Mar 20, 2012 6:39 pm
Posts: 76
Certs: CCNA, CCNA Security, FIREWALL v2.0
How about using a proxy server? There is some pretty good software out there that will allow you to see real time traffic, routing through the proxy.


Top
 Profile  
 
PostPosted: Fri Mar 23, 2012 1:17 am 
Offline
New Member
New Member

Joined: Wed Aug 24, 2011 4:11 pm
Posts: 30
Certs: CCENT,Network+
I would also like to know the answer to this. Does anyone know if there is a tool like torch on RouterBoard? http://i294.photobucket.com/albums/mm90 ... torch2.jpg

Thanks for all the info above as well!


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 15 posts ] 

All times are UTC - 6 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 2 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB® Forum Software © phpBB Group