cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
578
Views
0
Helpful
2
Replies

Checking connections and Security

aLeffingwell
Level 1
Level 1

Hey All,

I need to check the connections through our ASA5510, look for anything 'abnormal', and check things like FTP and Telnet sessions going on over our firewall.

Currently I've been using 'show local-host brief' to see high numbers of connections, then I go back through and do 'show local-host x.x.x.x' to see what they're actually connected to. 

I'm seeing some desktops with 120+ TCP connections, but when I do a 'show local-host x.x.x.x' on those IP's I get a long list, but it's all to normal sites like google, facebook etc. 

I'm also currently doing things all by hand, visually looking at the IP's, doing whois on them etc..

Here are my questions:

  1. What is 'abnormal' and what are some tools to find abnormalities
  2. Is there a way to pull all the IP's on the inside/outside interfaces and scan them against known bad IP's/malicious IP's??
  3. How do I identify users who are hogging bandwidth / doing things they shouldn't be by looking at the results of 'show local-host' (how many connections is 'too many')
  4. How do I specifically look for FTP sessions or Telnet sessions going through our firewall?

Any answers on any of these would be a huge help for my daily reports !!

1 Accepted Solution

Accepted Solutions

lordbigsack
Level 1
Level 1

for statistical analysis I would recommend setting up cacti graphing to monitor your ASA and for more indepth tracking of what user has done what then I would have thought netflow would be the ideal candidate.

netflow setup for asa:

http://www.cisco.com/en/US/docs/security/asa/asa83/netflow/netflow.html

hth

Scott

View solution in original post

2 Replies 2

lordbigsack
Level 1
Level 1

for statistical analysis I would recommend setting up cacti graphing to monitor your ASA and for more indepth tracking of what user has done what then I would have thought netflow would be the ideal candidate.

netflow setup for asa:

http://www.cisco.com/en/US/docs/security/asa/asa83/netflow/netflow.html

hth

Scott

Hey LBS,

Cleaning up some of my old/un-resolved discussions.  Your recommendation was a good one, thanks for your help!

Kindest Regards,

ALAN

Review Cisco Networking products for a $25 gift card