Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
New Member

Monitoring Network Traffic

We have a Cisco ASA5510 in place. We currently do not have any additional network monitoring tools in place other than the tools on the ASA itself and wireshark.

Lateley our connection to \ from the internet has been getting maxed out, when looking at the outside interface graph on the ASA it shows a straight line accross the top at the maxed out limit.

How can I determine, in real time who is killing our internet?

Please help

2 REPLIES

Re: Monitoring Network Traffic

1.You can use threat detection

http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/protect.html#wp1058499

What you need is:

threat-detection statistics host

threat-detection statistics port

threat-detection statistics protocol

2. You can use netflow from ASA version 8.2

New Member

Re: Monitoring Network Traffic

NetFlow from ASA is currently not supported by most of the NetFlow based tool vendors. NetFlow from ASA devices, termed as NetFlow Secure Event Logging (NSEL) is based on NetFlow version 9.

The NSEL is based on events triggered on the firewall devices and is different from the normal NetFlow packets. These packets do not have information which can be used properly for traffic monitoring.

You may have to wait for a bit longer for vendors to start supporting this new NetFlow.

157
Views
0
Helpful
2
Replies
CreatePlease to create content