09-25-2012 07:56 AM - edited 03-11-2019 04:58 PM
hi Friends,
We ahave ASA 5510 and 5520 @ our office. We are not using any netflow tools in order to get the talk talklers.
As this firewalls are shared firewall (used by different Projects), we are not able to get , which project is using more traffic and which is less.
Can someone help me out in this ?
Regards
Nirav Bhatt
09-27-2012 07:08 AM
Hi Nirav,
You can some of the information you are looking for with thread-detection.. On the ASA you can find the top 10 souces, top 10 destination, and most used protocols on the network.
http://www.cisco.com/en/US/docs/security/asa/asa80/asdm60/user/guide/protect.html#wpxref82650
Luis
04-30-2013 01:24 AM
I know this is an old thread, but I'm hoping this will come in handy for anyone doing a search.
All our 5505's and 5510's are on ASA 8.2(5) and didn't get some of the nicer "top 10" features that come with later versions. I always assumed it was due to the ASA version, but I built an ASA recently on 8.2(5) which has ASDM 7.1(2) on it and the pie charts for top talkers is there now.
I'm in the process of updating all our devices to ASDM 7.1(2) and it's given us a lot more visibility of the network.
05-17-2013 04:13 PM
That is great! Go for it!
Luis Silva
07-01-2013 06:54 AM
Hi Nirav,
If you've got a linux server, you can copy/past the "show conn" command output in a file and just use the awk command :
cat /tmp/ASA_show_conn_ouput |awk '{print $9, $1, $3, $5}' |sort -nr | head -10
You will get the TOP10 connexions by nb of bytes.
Vincent
01-28-2016 07:48 AM
Thanks Vicent, this trick is excellent!.
11-30-2017 07:56 AM
In "show conn " we have 700k entries, how do i take it over linux machine?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide