05-17-2018 03:19 AM - edited 02-21-2020 07:46 AM
Hi,
Is there any option in firepower2110 to know the source/host IP's, which are hitting my outside interface from inside along with using application.
05-17-2018 05:47 AM
Assuming you are logging connections then yes. Just filter the analysis > connections table to include only the inside subnets in the source field and outside address in the destination field.
05-17-2018 09:54 PM
Thanks Marvin for the reply.
Actually, i have seen increase in traffic on one of my firepower outside interface directly connected with ISP but unable to trace which source IP is hitting that interface and for which application it is using to increase in sudden traffic.
05-18-2018 06:34 AM
Do you have any identity integration (like via ISE or AD Agent)? If so, you should be able to see the "Traffic by User" widget in your summary dashboard.
You can also look at the "Top Client Applications Seen" widget for additional information.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide