We have a PIX-525 running 6.3.5 that is configured for our DMZ & Internet firewall.
e0 = Internet
e1 = DMZ
e2 = LAN
We have a number of static NATs configured for public facing servers and a PAT address for user Internet traffic.
I've been asked to find which internal hosts are consuming the most bandwidth on our network. I checked and it doesn't look like the PIX supports netflow.
Is there a way that I can export the "show xlate" output to a file and sort so as to find which host is being translated the most?
I read a post somewhere about turning logging up on the pix to informational and then review the syslogs for translations/connections being built. Not sure how that may work.
Is there a better way to do this? I'd like to script something if possible but have to admit I'm a noob when it comes to running/writing scripts.
Thanks for the help.