Avatar of rootdude
rootdude
 asked on

Who Cratered the Internet?

Hey Guys -

Is there any way on an ASA 5510 to find out what user has cratered the internet connection? I know all about netflow, and that it isn't supported, but is there any other way to tell which IP address is pulling the most data?

Thanks!
Stac
Hardware FirewallsCisco

Avatar of undefined
Last Comment
agriesser

8/22/2022 - Mon
raptorjb007

The ADSM should be able to give you some basic charts and graphs regarding traffic. You may want to try this first if all you need is a basic idea.

Other than this you would need to implement a traffic sniffer to listen to all traffic traversing the ASA. The ASA's support monitor ports so this should not be an issue.
sharedit

in the asdm there are some monitoring statistics. not sure how detailed they are, I could check for you.

you could enable the logging and just watch for the ip sending the most traffic

All in the ASDM which Im sure you know can be accessed through yr web browser  https://(internal IP of the ASA)
rootdude

ASKER
Gentlemen - thanks for the comments - perhaps I should have been more specific. I need to watch the aggregate and / or the immediate packet rates for internal ip addresses. I need to map traffic back to specific ip addresses.
I started with Experts Exchange in 2004 and it's been a mainstay of my professional computing life since. It helped me launch a career as a programmer / Oracle data analyst
William Peck
SOLUTION
raptorjb007

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
GET A PERSONALIZED SOLUTION
Ask your own question & get feedback from real experts
Find out why thousands trust the EE community with their toughest problems.
raptorjb007

I do not think Wireshark has any ability to give you advanced reports, however the more advanced traffic analyzer packages come with better reporting capabilities.
Cyclops3590

if you have a managed switch that can do mirroring of ports, you can use ntop.  just mirror the switch port the firewall is connected to, to the sniffer server with ntop.  
agriesser

⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
rootdude

ASKER
Hmmm - so it's possible that by upgrading the image on the firewall so I get ASDM 6 that I may have what I'm looking for? The version of ASDM I'm currently being presented with is 5.2... does thta make sense to our experts?
ASKER CERTIFIED SOLUTION
agriesser

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.