?
Solved

ISA2003-report for bandwith

Posted on 2007-04-05
6
Medium Priority
?
259 Views
Last Modified: 2013-12-04
hello all.
I'm using an ISA 2003 firewall between my LAN and internet. My LAN has around 400 clients. now I have problem: some of users is infected with spyware, and it sends many mails, and use most the bandwith.

Using ISA 2003, how can I detech who is infected with spyware? or saying in other way, who use most my bandwith?

regard
hva.
0
Comment
Question by:hva123456
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 2
6 Comments
 
LVL 51

Accepted Solution

by:
Keith Alabaster earned 2000 total points
ID: 18857051
No such thing as ISA 2003 - its isa2000, 2004 or 2006.
If its isa2000 then you can use the bandwidth options and the ISA log files.

If its ISA2004 or ISA2006, the bandwidth control was removed.
Instead, open the ISA gui,
select monitoring - reports
Create and run a report for the required period and this will produce a decent html report of all activity, to where and by whom and from where.
Also, in the gui, select monitoring - logging.
click start query - this starts the live logging (realtime) monitor.
0
 

Author Comment

by:hva123456
ID: 18862639
The problem is we cannot have a report on a specific port for each user
0
 
LVL 51

Expert Comment

by:Keith Alabaster
ID: 18862676
Again, what version of ISA are you actually running? Bandwidth reporting is not provided in isa2004/2006 so is not an isa fault; its a feature :)
There are add-ons/plug-ins that can be purchased to provide that functionality though.


0
Need protection from advanced malware attacks?

Look no further than WatchGuard's Total Security Suite, providing defense in depth against today's most headlining attacks like Petya 2.0 and WannaCry. Keep your organization out of the news with protection from known and unknown threats.

 

Author Comment

by:hva123456
ID: 18879998
I use ISA 2004,. So we dont have the solution at the moment?
0
 
LVL 51

Assisted Solution

by:Keith Alabaster
Keith Alabaster earned 2000 total points
ID: 18880569
<<If its ISA2004 or ISA2006, the bandwidth control was removed.
Instead, open the ISA gui,
select monitoring - reports
Create and run a report for the required period and this will produce a decent html report of all activity, to where and by whom and from where.
Also, in the gui, select monitoring - logging.
click start query - this starts the live logging (realtime) monitor>>

If you want it more granular then goto the monitoring - logging section.
Edit the Query to use the criteria you want reported against and the time action to cover the period to report against. Select a single user if you wish
open the toolbox window on the right and select copy all to clipboard
Copy this into Excel and you can graph it to your hearts content.

Lastly, the data is all stored in an MSDE database. You can query this directly on the ISA box (ISA's security features will stop you querying the msde from another machine) to pull the info as you want.

As mentioned, ISA does not perform bandwidth loading so it is not a function of the product.


0
 
LVL 51

Expert Comment

by:Keith Alabaster
ID: 19036619
Thanks :)
0

Featured Post

Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This is a guide to the following problem (not exclusive but here) on Windows: Users need our support and we supporters often use global administrative accounts to do this. Using these accounts safely is a real challenge. Any admin who takes se…
The term "Bad USB" is a buzz word that is usually used when talking about attacks on computer systems that involve USB devices. In this article, I will show what possibilities modern windows systems (win8.x and win10) offer to fight these attacks wi…
In this brief tutorial Pawel from AdRem Software explains how you can quickly find out which services are running on your network, or what are the IP addresses of servers responsible for each service. Software used is freeware NetCrunch Tools (https…
In this video, Percona Solution Engineer Dimitri Vanoverbeke discusses why you want to use at least three nodes in a database cluster. To discuss how Percona Consulting can help with your design and architecture needs for your database and infras…
Suggested Courses

765 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question