I have cisco ASA 5520 and i am having high traffic per hour from my internal interface, For example can have 700 or 800 MB, this behavior come happening since 3 weeks ago.
Can someone help me to know whats is happening?
Thank in advance
Please make sure that the below commands are in your configuration:
threat-detection statistics port
threat-detection statistics protocol
threat-detection statistics access-list
threat-detection statistics tcp-intercept rate-interval 30 burst-rate 400
If these are present, then when you go to the firewall dashboard on the
ASDM, it will show you top 10 services, top 10 sources, and top 10
destinations. One limitation is that while you can get these statistics in
general, you might have to use different techniques (like sniffing the
traffic using wireshark) to actually look at the type of traffic for top
Hope this helps.