<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic What is it mean? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/what-is-it-mean/m-p/2112266#M357288</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Seems to me that some host/hosts are generating alot of traffic from your LAN through the ASA to the Internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there some backups been taken of servers that use the Internet connection? I'm not familiar with the process of backing up servers but I'd assume you could configure it to work so that it cant hog so much bandwith even though used outside normal working hours.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If this traffic is not caused by some traffic that is "normal" I would suggest monitoring the active connections on the ASA and then determining the hosts generating this traffic and removing them from the network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 30 Jan 2013 20:38:53 GMT</pubDate>
    <dc:creator>Jouni Forss</dc:creator>
    <dc:date>2013-01-30T20:38:53Z</dc:date>
    <item>
      <title>What is it mean?</title>
      <link>https://community.cisco.com/t5/network-security/what-is-it-mean/m-p/2112264#M357286</link>
      <description>&lt;P&gt;Hi, please see attach diagram.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My network always have connection problem everyday around 4.30 - 5.00 pm.&lt;/P&gt;&lt;P&gt;Attach are the screenshot i took photo of my ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The place i highlighted, what does it mean actually??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;We are trying to find the root cause of the connectivity problem??&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 00:54:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/what-is-it-mean/m-p/2112264#M357286</guid>
      <dc:creator>Mohd Khairul Nizam</dc:creator>
      <dc:date>2019-03-12T00:54:41Z</dc:date>
    </item>
    <item>
      <title>Re: What is it mean?</title>
      <link>https://community.cisco.com/t5/network-security/what-is-it-mean/m-p/2112265#M357287</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are you running a back-up to a external location? Which starts at the time you are saying?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Jan 2013 20:35:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/what-is-it-mean/m-p/2112265#M357287</guid>
      <dc:creator>Bart Kersten</dc:creator>
      <dc:date>2013-01-30T20:35:02Z</dc:date>
    </item>
    <item>
      <title>What is it mean?</title>
      <link>https://community.cisco.com/t5/network-security/what-is-it-mean/m-p/2112266#M357288</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Seems to me that some host/hosts are generating alot of traffic from your LAN through the ASA to the Internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there some backups been taken of servers that use the Internet connection? I'm not familiar with the process of backing up servers but I'd assume you could configure it to work so that it cant hog so much bandwith even though used outside normal working hours.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If this traffic is not caused by some traffic that is "normal" I would suggest monitoring the active connections on the ASA and then determining the hosts generating this traffic and removing them from the network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Jan 2013 20:38:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/what-is-it-mean/m-p/2112266#M357288</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-01-30T20:38:53Z</dc:date>
    </item>
    <item>
      <title>What is it mean?</title>
      <link>https://community.cisco.com/t5/network-security/what-is-it-mean/m-p/2112267#M357289</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Seems actually according to the "connections per second" that there is probably only 1 or a very low amount of hosts on the network that could be causing this problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would consider using the command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"show conn long"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then looking at the output look for connections that have been active for a while and also connections that have so far transfered alot of data. As we can see the data rate is pretty high so the culprit host should be easy to determine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Jan 2013 20:43:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/what-is-it-mean/m-p/2112267#M357289</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-01-30T20:43:08Z</dc:date>
    </item>
    <item>
      <title>What is it mean?</title>
      <link>https://community.cisco.com/t5/network-security/what-is-it-mean/m-p/2112268#M357290</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all, &lt;/P&gt;&lt;P&gt;Thank for the respone.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we dont have any backup to external. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Lately we are having problem during that specified time.&lt;/P&gt;&lt;P&gt;I want to catch / isolate the culprit&lt;/P&gt;&lt;P&gt;I attach some more pictures. i dont know to interpret the graph and data.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pls help?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/9/8/6/127689-1.JPG" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/0/9/6/127690-2.JPG" class="jive-image" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Feb 2013 07:36:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/what-is-it-mean/m-p/2112268#M357290</guid>
      <dc:creator>Mohd Khairul Nizam</dc:creator>
      <dc:date>2013-02-01T07:36:40Z</dc:date>
    </item>
    <item>
      <title>What is it mean?</title>
      <link>https://community.cisco.com/t5/network-security/what-is-it-mean/m-p/2112269#M357291</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;172.27.17.8 sends bunch of traffic to 122.152.181.147.&lt;/P&gt;&lt;P&gt;You have to check what's 172.27.17.8 on your network and find out why it does that.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Feb 2013 08:36:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/what-is-it-mean/m-p/2112269#M357291</guid>
      <dc:creator>Andrew Phirsov</dc:creator>
      <dc:date>2013-02-01T08:36:21Z</dc:date>
    </item>
    <item>
      <title>What is it mean?</title>
      <link>https://community.cisco.com/t5/network-security/what-is-it-mean/m-p/2112270#M357292</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;you can use &lt;STRONG&gt;shun&lt;/STRONG&gt; command to shutdown/close the&amp;nbsp; connection temporary for that particular ip, you can also use &lt;STRONG&gt;capture &lt;/STRONG&gt;command to monitor/capture the traffic that is causing this, can you also provide the picture for top 10 services?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Feb 2013 09:18:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/what-is-it-mean/m-p/2112270#M357292</guid>
      <dc:creator>Rudy Sanjoko</dc:creator>
      <dc:date>2013-02-01T09:18:39Z</dc:date>
    </item>
    <item>
      <title>Re: What is it mean?</title>
      <link>https://community.cisco.com/t5/network-security/what-is-it-mean/m-p/2112271#M357293</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i belive the top 10 services is HTTP and HTTPS. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Only web services but can generate so much traffic. I wonder??&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Feb 2013 06:31:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/what-is-it-mean/m-p/2112271#M357293</guid>
      <dc:creator>Mohd Khairul Nizam</dc:creator>
      <dc:date>2013-02-04T06:31:13Z</dc:date>
    </item>
    <item>
      <title>What is it mean?</title>
      <link>https://community.cisco.com/t5/network-security/what-is-it-mean/m-p/2112272#M357294</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As Andrew above said.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You should locate the host with the IP address of 172.27.17.8 behind the ASA that seems to be generating the highest amount of the connections. Then go through that host computer and see what is causing the high amount of connections.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you only want to use the graphical user interface (ASDM) to troubleshoot this, I would recomment trying to use the real time logging in the ASDM to see what happens when the problem is on.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To view the logs in real time go to the following place in the ASDM&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Monitor -&amp;gt; Logging -&amp;gt; View&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can then enter the source IP address and apply it as the filter and only see logs for it. Though I'm not sure how the ASDM works when the problem is on as the host on the LAN seems to push as much traffic to the Internet as the interface is able to transmit. This might make it impossible to use ASDM&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would also suggest configuring a Syslog server to the LAN if possible to store the log data for later reference.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the ASA CLI you can issue the following commands to see the connections&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"show conn"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"show conn long"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"show local-host 172.27.17.8"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the host 172.27.17.8 is NOT a server you could try to remove it from the network temporarily and see if the problem appears again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Feb 2013 11:42:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/what-is-it-mean/m-p/2112272#M357294</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-02-04T11:42:00Z</dc:date>
    </item>
  </channel>
</rss>

