cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2284
Views
0
Helpful
4
Replies

Firewall Traffic Monitoring..

vipin kumar
Beginner
Beginner

Dear All,

I am new to the PIX firewall. And recently implemented the PIX 506e in my network. I wants to know how we can monitor the system that is generating the more traffic on Network through Firewall. Thanks for any help..

1 Accepted Solution

Accepted Solutions

saquib.tandel
Beginner
Beginner

Hello

we monitor firewall traffic using Fireplotter tool. For more details please www.fireplotter.com.

If you firewall was ASA 5510 then you can monitor via ASDM

thanks

ST

View solution in original post

4 Replies 4

saquib.tandel
Beginner
Beginner

Hello

we monitor firewall traffic using Fireplotter tool. For more details please www.fireplotter.com.

If you firewall was ASA 5510 then you can monitor via ASDM

thanks

ST

sean_evershed
Rising star
Rising star

Hi,


An alternative would be to configure Netflow on your inside router that connects to the firewall. Then use a product like Manage Engine to monitor the traffic flows through your network.

http://www.manageengine.com/

The disadvantage of this approach is that it will show all traffic passing through your network, from both the inside and the outside. This might not be a bad thing however as it is an excellent tool for troubleshooting virus outbreaks, slow network performance etc.

Please remember to rate all posts that are helpful.

hobbe
Rising star
Rising star

The short answer is The pix 506E does not support that in itself.

There are some ways to go around that problem.

Management software such as fireplotter that checks status tables and makes a "complete" picture of usage, as suggested before.

Switch with span port and a software to monitor and map what your firewall is sending on both interfaces to get the complete picture and on inside to see who is using what bandwith to do what.

Monitoring the router on the inside with fx netflow as suggested before 

Replace the 506 with a asa5505 with up to date software where you have "top talkers" and so on, and even "netflow".

My vote would go for the last solution ie buying a asa5505

Good luck

HTH

vipin kumar
Beginner
Beginner

Thanks to provide the detail about fireplotter tool....

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Recognize Your Peers