08-05-2005 11:05 AM - edited 02-21-2020 12:18 AM
is there a way on the PIX to find a user on the internal side that is consuming most the of your public bandwidth ?
I have used the sho conn but its a busy firewall and hard to go thru all of the list
08-05-2005 02:35 PM
Hi,
Probably the easiest way to do this is to use netflow on a router.
Maybe you have a router on the internet side of the PIX?
I'm hoping a previous post can help you:
Rgds
PJD
08-10-2005 05:13 AM
Well I have managed to narrow down the the huge "sh conn" list by using the command sh conn | grep 0.00:00 which just shows me all the active connections that are not idle..I then look at the byte value to show me which IP is int he process of transfering a large amount of data..Its pretty easy to see it this way
So far I have been able to catch a few employees downloading huge Video files this way..
Cheers
DCLEE
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide