Solved

Track High Bandwidth Usage Across VPN

Posted on 2012-03-19
2
1,009 Views
Last Modified: 2012-03-19
I'm looking for something to track what is using up bandwidth from some of our remote offices.  It's causing the entire site to bottleneck, with ~500ms reply times, for what normally should be ~50ms across high speed cable and dsl links.  I'm using all Sonicwall VPN appliances.  Thank you.
0
Comment
Question by:fireguy1125
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 2

Accepted Solution

by:
BigRMV earned 500 total points
ID: 37738540
The first thing I would suggest is to contact your broadband provider and find out if they have a tool that tracks usage, high usage periods, and can show you whether or not your line is reaching the saturation point.

As for SonicWALL, you should log into the unit's GUI as the administrator.  Then use the system diagnostics to see who/what is using the most bandwidth.  For example:

-- Log into the GUI
-- Click the SYSTEM tab on the left
-- Click the DIAGNOSTICS item
-- At the DIAGNOSTICS TOOL pull down menu, select ACTIVE CONNECTIONS MONITOR
-- By default, the options will be Protocol: ALL PROTOCOLS, Src Interface: ALL INTERFACES, and DST Interface: ALL INTERFACES.
-- At the top-right of the generated list, you'll see TX BYTES and RX BYTES. You can click those title bar items to sort highest to lowest or vice versa.
-- Click the EXPORT RESULTS button to save these results to a CSV file for future reference.

The first few "hogs" on your list should be your most active machines (Exchange servers, SQL servers, etc.).  After that are you most active users.

You can filter the Active Connections results further by changing the options.  On most SonicWALL devices, X0 will be your LAN, X1 will be the WAN, and X2 and beyond will be VPNs DMZs and so on.

With these givens, you can track inbound VPN usage by selecting Protocol: ALL PROTOCOLS, Src Interface: X2, and Dst Interface: X0.  You can find outbound by switching the Src and Dst interface options.  (see attached).  Export these results for future reference, too.

Note that you can also choose the LOG tab to view your activity log.  Check this to make sure that you're not being attacked or if you think that one of your users' activities could be the root of your problems.

This can become a lengthy process because you have to do all of the checking/reviewing to try to isolate the cause.  So you'll have to be familiar with your system, the IP addresses in use, the protocols you allow or don't, and how much traffic you should expect from each versus what you see in these results in order to find any meaningful patterns.
0
 
LVL 1

Author Closing Comment

by:fireguy1125
ID: 37738562
Perfect, I saw that several PCs were pulling new antivirus definitions from the parent server over the VPN connection! Thanks!
0

Featured Post

Building an interactive eFuture classroom

Watch and learn how ATEN provided a total control system solution including seamless switching matrix switch, HDBaseT extenders, PDU, lighting control to build an interactive eFuture classroom.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Secure VPN Connection terminated locally by the Client.  Reason 442: Failed to enable Virtual Adapter. If you receive this error on Windows 8 or Windows 8.1 while trying to connect with the Cisco VPN Client then the solution is a simple registry f…
Are you one of those front-line IT Service Desk staff fielding calls, replying to emails, all-the-while working to resolve end-user technological nightmares? I am! That's why I have put together this brief overview of tools and techniques I use in o…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

717 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question