<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Monitoring traffic in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/monitoring-traffic/m-p/4910305#M1103717</link>
    <description>&lt;P&gt;I agree with &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/178747"&gt;@Flavio Miranda&lt;/a&gt; - Netflow is your friend here. You can setup a free PTRG instance to collect Netflow exported from the ASA and easily see the top sources/destinations of traffic. Looking at the ASA directly won't show you that sort of info. You can certainly see CPU, memory, connections, etc. but mostly only a a point in time for connections/ flows and that's what you need in this case.&lt;/P&gt;</description>
    <pubDate>Wed, 23 Aug 2023 05:55:32 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2023-08-23T05:55:32Z</dc:date>
    <item>
      <title>Monitoring traffic</title>
      <link>https://community.cisco.com/t5/network-security/monitoring-traffic/m-p/4910225#M1103712</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I recently got a complain on the internet streaming through our internal network going out to Youtube or Facebook.&lt;/P&gt;&lt;P&gt;In the normal hours, we are working fine, no one complain about the traffic or the streaming, smooth on everything.&lt;/P&gt;&lt;P&gt;But during some time in the afternoon, we noticed that the traffic of our internet spike to over 500MB. It affects our streaming. And becoming choppy.&lt;/P&gt;&lt;P&gt;Is there any way we can find out the where are the inbound / outbound traffic? I have the Zabbix monitoring server, and now can only show the traffic being burst. But can I find out what is inside?&lt;/P&gt;&lt;P&gt;The graph below shows the spike in the afternoon the day before. The one in the morning is also doing the same thing, but we don't experience any choking on the networks/streaming. Both time we do the streaming.&lt;/P&gt;&lt;P&gt;Can give me some idea on how to find the traffic out?&lt;/P&gt;&lt;P&gt;We have C2960XR as the switches, and ASA5516 as the firewall.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Traffic_FW.JPG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/194948i562AD4D239FAF5BE/image-size/large?v=v2&amp;amp;px=999" role="button" title="Traffic_FW.JPG" alt="Traffic_FW.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Aug 2023 23:12:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/monitoring-traffic/m-p/4910225#M1103712</guid>
      <dc:creator>timothy_MTS</dc:creator>
      <dc:date>2023-08-22T23:12:36Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring traffic</title>
      <link>https://community.cisco.com/t5/network-security/monitoring-traffic/m-p/4910229#M1103713</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1466906"&gt;@timothy_MTS&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;In order to see traffic you can enable netflow on the switch. Send the flow to a server. You can use free tools like Grafana in order to graphic the output.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;There are others alternative on the internet, this is just an example.&lt;/P&gt;
&lt;P&gt;Another thing to check is if the firewall is able to handle all the connections properly.&amp;nbsp; UDP traffic like streaming can saturate firewall easily. Check firewall capacity.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Aug 2023 23:21:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/monitoring-traffic/m-p/4910229#M1103713</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2023-08-22T23:21:50Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring traffic</title>
      <link>https://community.cisco.com/t5/network-security/monitoring-traffic/m-p/4910266#M1103716</link>
      <description>&lt;P&gt;Thanks &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/178747"&gt;@Flavio Miranda&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ok. True that we need something to monitor / analyze on what's going on.&lt;/P&gt;&lt;P&gt;But from the Firewall itself, does it have anything that I can check besides the CPU, Memory. What I am thinking, if traffic going through the interfaces of the firewall, no matter just a short period of time, not those history.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Aug 2023 02:33:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/monitoring-traffic/m-p/4910266#M1103716</guid>
      <dc:creator>timothy_MTS</dc:creator>
      <dc:date>2023-08-23T02:33:29Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring traffic</title>
      <link>https://community.cisco.com/t5/network-security/monitoring-traffic/m-p/4910305#M1103717</link>
      <description>&lt;P&gt;I agree with &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/178747"&gt;@Flavio Miranda&lt;/a&gt; - Netflow is your friend here. You can setup a free PTRG instance to collect Netflow exported from the ASA and easily see the top sources/destinations of traffic. Looking at the ASA directly won't show you that sort of info. You can certainly see CPU, memory, connections, etc. but mostly only a a point in time for connections/ flows and that's what you need in this case.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Aug 2023 05:55:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/monitoring-traffic/m-p/4910305#M1103717</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2023-08-23T05:55:32Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring traffic</title>
      <link>https://community.cisco.com/t5/network-security/monitoring-traffic/m-p/4910477#M1103724</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1466906"&gt;@timothy_MTS&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Asa support netflow, you can enable in both devices although they will see the same information.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Aug 2023 07:59:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/monitoring-traffic/m-p/4910477#M1103724</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2023-08-23T07:59:10Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring traffic</title>
      <link>https://community.cisco.com/t5/network-security/monitoring-traffic/m-p/4911651#M1103798</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/178747"&gt;@Flavio Miranda&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/326046"&gt;@Marvin Rhoads&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Having successfully plot the Netflow information to the PRTG analyze tool. It gives a great picture on it.&lt;/P&gt;&lt;P&gt;Next will fine tune it to have 24 7 monitoring. Thank you for the great help.&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Timothy&lt;/P&gt;</description>
      <pubDate>Thu, 24 Aug 2023 22:43:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/monitoring-traffic/m-p/4911651#M1103798</guid>
      <dc:creator>timothy_MTS</dc:creator>
      <dc:date>2023-08-24T22:43:03Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring traffic</title>
      <link>https://community.cisco.com/t5/network-security/monitoring-traffic/m-p/4911657#M1103799</link>
      <description>&lt;P&gt;that´s great &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1466906"&gt;@timothy_MTS&lt;/a&gt;&amp;nbsp; glad to hear you suceeded&lt;/P&gt;</description>
      <pubDate>Thu, 24 Aug 2023 23:31:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/monitoring-traffic/m-p/4911657#M1103799</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2023-08-24T23:31:43Z</dc:date>
    </item>
  </channel>
</rss>

