<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA top talkers in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-top-talkers/m-p/3212977#M1065006</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I obtained this data form the firewall dashboard. I don't unterstand why i see as source pubblic ip address. Can you explain me ?&lt;/P&gt;
&lt;P&gt;The top user section doesn't work because I don't have the AD connected to asa.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="fwdash.PNG" style="width: 808px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/3034i52EE9E14B4AA2D17/image-size/large?v=v2&amp;amp;px=999" role="button" title="fwdash.PNG" alt="fwdash.PNG" /&gt;&lt;/span&gt;Thank you,&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Daniele&lt;/P&gt;</description>
    <pubDate>Wed, 08 Nov 2017 10:18:52 GMT</pubDate>
    <dc:creator>pugliededaniele88</dc:creator>
    <dc:date>2017-11-08T10:18:52Z</dc:date>
    <item>
      <title>ASA top talkers</title>
      <link>https://community.cisco.com/t5/network-security/asa-top-talkers/m-p/3210421#M1065002</link>
      <description>&lt;P&gt;Dear all,&lt;/P&gt;
&lt;P&gt;from PRTG monitoring a saw that many time the bandwith of my connection is full. I need to know what is the clients that generating more traffic. Is there&amp;nbsp; a method to know this ? from ASDM or CLI ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Daniele.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 14:38:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-top-talkers/m-p/3210421#M1065002</guid>
      <dc:creator>pugliededaniele88</dc:creator>
      <dc:date>2020-02-21T14:38:18Z</dc:date>
    </item>
    <item>
      <title>Re: ASA top talkers</title>
      <link>https://community.cisco.com/t5/network-security/asa-top-talkers/m-p/3210429#M1065003</link>
      <description>&lt;P&gt;You can do this on the ASDM using the Firewall Dashboard. Under Home tab, Navigate to the Firewall Dashboard tab and enable the Top Usage Stats dashboard on the right hand section. You can then see this information in bar, pie or table format.&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="topn-asdm.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/2886i5AEC98915DEEF39D/image-size/large?v=v2&amp;amp;px=999" role="button" title="topn-asdm.PNG" alt="topn-asdm.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Nov 2017 14:26:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-top-talkers/m-p/3210429#M1065003</guid>
      <dc:creator>Rahul Govindan</dc:creator>
      <dc:date>2017-11-03T14:26:40Z</dc:date>
    </item>
    <item>
      <title>Re: ASA top talkers</title>
      <link>https://community.cisco.com/t5/network-security/asa-top-talkers/m-p/3210463#M1065004</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;I found the section but the monitoring stay in stuck on loading. I will wait if I can obtain the information...&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Thank you,&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;For your help !&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 03 Nov 2017 15:23:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-top-talkers/m-p/3210463#M1065004</guid>
      <dc:creator>pugliededaniele88</dc:creator>
      <dc:date>2017-11-03T15:23:58Z</dc:date>
    </item>
    <item>
      <title>Re: ASA top talkers</title>
      <link>https://community.cisco.com/t5/network-security/asa-top-talkers/m-p/3210557#M1065005</link>
      <description>&lt;P&gt;Usually takes a while to populate some of the dashboards as the default period is 1 hour for most of them.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Nov 2017 17:13:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-top-talkers/m-p/3210557#M1065005</guid>
      <dc:creator>Rahul Govindan</dc:creator>
      <dc:date>2017-11-03T17:13:43Z</dc:date>
    </item>
    <item>
      <title>Re: ASA top talkers</title>
      <link>https://community.cisco.com/t5/network-security/asa-top-talkers/m-p/3212977#M1065006</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I obtained this data form the firewall dashboard. I don't unterstand why i see as source pubblic ip address. Can you explain me ?&lt;/P&gt;
&lt;P&gt;The top user section doesn't work because I don't have the AD connected to asa.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="fwdash.PNG" style="width: 808px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/3034i52EE9E14B4AA2D17/image-size/large?v=v2&amp;amp;px=999" role="button" title="fwdash.PNG" alt="fwdash.PNG" /&gt;&lt;/span&gt;Thank you,&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Daniele&lt;/P&gt;</description>
      <pubDate>Wed, 08 Nov 2017 10:18:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-top-talkers/m-p/3212977#M1065006</guid>
      <dc:creator>pugliededaniele88</dc:creator>
      <dc:date>2017-11-08T10:18:52Z</dc:date>
    </item>
    <item>
      <title>Re: ASA top talkers</title>
      <link>https://community.cisco.com/t5/network-security/asa-top-talkers/m-p/3213007#M1065007</link>
      <description>&lt;P&gt;You see public IP's as the source address as the traffic is likely originating from the internet and going to you. For example someone in your lan is downloading something from that source address and the ASDM is reporting that a lot of traffic is coming from that IP. Also it could mean that someone at that source IP is sending that data into your network if you have a service setup to receive that data (ftp or sftp server?).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As you have PRTG you could&amp;nbsp;configure netflow on the ASA and have it send the traffic information data to PRTG &amp;amp; PRTG can then compile a list of top talkers for you,&amp;nbsp;you then won't need to have ASDM constantly open. Netflow on PRTG will be much more useful to you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportforums.cisco.com/t5/security-documents/configuring-netflow-on-asa-with-asdm/ta-p/3119466" target="_blank"&gt;https://supportforums.cisco.com/t5/security-documents/configuring-netflow-on-asa-with-asdm/ta-p/3119466&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;PRTG support doc on configuring netflow on ASA 55XX series.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://kb.paessler.com/en/topic/1423-how-to-monitor-cisco-asa-firewalls-using-netflow-9-and-prtg" target="_blank"&gt;https://kb.paessler.com/en/topic/1423-how-to-monitor-cisco-asa-firewalls-using-netflow-9-and-prtg&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Nov 2017 11:31:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-top-talkers/m-p/3213007#M1065007</guid>
      <dc:creator>chris phillips</dc:creator>
      <dc:date>2017-11-08T11:31:27Z</dc:date>
    </item>
    <item>
      <title>Re: ASA top talkers</title>
      <link>https://community.cisco.com/t5/network-security/asa-top-talkers/m-p/3213769#M1065008</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I tried to configure netflow on ASA but the following&amp;nbsp; command&amp;nbsp; seems doesn't works&lt;/P&gt;
&lt;PRE&gt;policy-map global_policy
class class-default
flow-export event-type all destination x.x.x.x yy&lt;/PRE&gt;
&lt;P&gt;The following error is showed &lt;/P&gt;
&lt;P&gt;Giulianova-FW# conf t&lt;BR /&gt;Giulianova-FW(config)# policy-map global_policy&lt;BR /&gt;Giulianova-FW(config-pmap)# class class-default&lt;BR /&gt;Giulianova-FW(config-pmap-c)# flow-export event-type all destination 10.111.1.$&lt;BR /&gt;&lt;BR /&gt;flow-export event-type all destination 10.111.1.102 2055&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ^&lt;BR /&gt;ERROR: % Invalid Hostname&lt;BR /&gt;Giulianova-FW(config-pmap-c)# $destination 10.111.1.102 ?&amp;nbsp; &amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;mpf-policy-map-class mode commands/options:&lt;BR /&gt;&amp;nbsp; Hostname or A.B.C.D&amp;nbsp; Destination IP address or name&lt;BR /&gt;&amp;nbsp; &amp;lt;cr&amp;gt;&lt;BR /&gt;Giulianova-FW(config-pmap-c)# $destination 10.111.1.102 &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;He ask me the ip address but I already put in the IP.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anyway after that I configured PRTG I can see the netflow protocol I don't know how but I see that. In the asa configuration I had configured only snmp. I don't unterstand how I can see netflow also...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Nov 2017 09:47:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-top-talkers/m-p/3213769#M1065008</guid>
      <dc:creator>pugliededaniele88</dc:creator>
      <dc:date>2017-11-09T09:47:26Z</dc:date>
    </item>
    <item>
      <title>Re: ASA top talkers</title>
      <link>https://community.cisco.com/t5/network-security/asa-top-talkers/m-p/3213806#M1065009</link>
      <description>&lt;P&gt;that is weird&amp;nbsp;that it works without the full config, PRTG is good but i don't think its good enough to defy the ASA config &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I can't test it right now but i'm wondering if you need the word "destination", maybe substitute "destination" for the actual IP.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;can you do a ? on the following and confirm?&lt;/P&gt;
&lt;P&gt;Giulianova-FW(config-pmap-c)# flow-export event-type all ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Nov 2017 11:02:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-top-talkers/m-p/3213806#M1065009</guid>
      <dc:creator>chris phillips</dc:creator>
      <dc:date>2017-11-09T11:02:34Z</dc:date>
    </item>
    <item>
      <title>Re: ASA top talkers</title>
      <link>https://community.cisco.com/t5/network-security/asa-top-talkers/m-p/3213942#M1065010</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;the destination command is needed:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Giulianova-FW(config)# policy-map global_policy&lt;BR /&gt;Giulianova-FW(config-pmap)# class class-default&lt;BR /&gt;Giulianova-FW(config-pmap-c)# flow-export event-type all ?&lt;BR /&gt;&lt;BR /&gt;mpf-policy-map-class mode commands/options:&lt;BR /&gt;&amp;nbsp; destination&amp;nbsp; Export specified NetFlow events to destination&lt;/P&gt;</description>
      <pubDate>Thu, 09 Nov 2017 14:44:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-top-talkers/m-p/3213942#M1065010</guid>
      <dc:creator>pugliededaniele88</dc:creator>
      <dc:date>2017-11-09T14:44:21Z</dc:date>
    </item>
  </channel>
</rss>

