PIX 501 Internet Usage Monitoring

Unanswered Question
Sep 19th, 2007

Hi,

We would like to monitor Internet usage on per-user basis, we have PIX 501 and users accessing the Internet via NAT.

What are the options?

As 501 does not support Netflow, can I use Syslog or SNMP getting usage stats?

Thank yoou.

Kind regards,

Alex

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
Jan Nejman Thu, 09/20/2007 - 04:16

Hello,

I'm worry, that you are not able to do a user monitoring on this kind of device. A SNMP gives you information about interface utilisation, but no user regarding information... Could you use any netflow capable switch before/after PIX? It is the first solution. But you lost information about real source user due to NAT. The another one solution is to use two switches (or a transparent netflow probes), the first one on ISP side and the second one in your internal network...

Kind regards,

Jan Nejman

Caligare Co.

http://www.caligare.com/

Actions

This Discussion