cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3514
Views
0
Helpful
4
Replies

Traffic Analysis - ASA

omer_babiker
Level 1
Level 1

Hi all,

If I noticed a lot of (incoming&outcoming) traffic in outside interface of ASA. Is there any way to know where is this traffic coming or going to (IP address)?

And if that traffic happened earlier (for example 1 day ago), can I still know the origin or destination IP address?

Please help!!

Thanks in Advance,

Omer

1 Accepted Solution

Accepted Solutions

The open source tool for capturing and analyzing netflow exports is ntop. Please see more information at http://www.ntop.org/products/ntop/

View solution in original post

4 Replies 4

Marvin Rhoads
Hall of Fame
Hall of Fame

There's no easy way to tell if you didn't already have instrumentation turned on.

The ASA is capable of exporting netflow data to an external collector. It is there that you would be able to retrospectively analyze top flows by source and destination address and port. Additionally in near real time you can monitor the top 10 hosts in the ASDM dashboard (or CLI equivalent).

Thanks Marvin for your reply.

Actually I asked this question because I've seen spiky load in my outside interface which looked suspicious. I was curious to know where it came from.

I used show conn command, but it was only showing the connections in use.

I'm using opennms as monitioring tool, but not sure if it will help in this case.

Any recommendation??

Thanks,

Omer

The open source tool for capturing and analyzing netflow exports is ntop. Please see more information at http://www.ntop.org/products/ntop/

Thanks for the valuable information

Review Cisco Networking products for a $25 gift card