Velocity Reviews - Computer Hardware Reviews

Velocity Reviews > Newsgroups > Computing > Cisco > How to find users abusing bandwidth?(pix firewall)

Reply
Thread Tools

How to find users abusing bandwidth?(pix firewall)

 
 
dogfrndnew@yahoo.com
Guest
Posts: n/a
 
      03-28-2007
I have a pix firewall(515 I believe) and every day at lunch and again
at the end of the day the Inet slows to a crawl. It is obviously a
user or group of users downloading a chunk of something. We have a
full T1 and during work hours, it functions fine. I would like to get
some software to possibly monitor the firewall and then point out the
heaviest user's IP. I have been playing around with syslogd, but have
not found a good way to cull through the log once it is written out.
I also have tried sawmill, and while it is a step in the right
direction, it is hard to believe there isn't a more direct way to
figure it out. Any thoughts? I have the powers above ready to buy if
I can find the right piece of software. thanks for your help.

 
Reply With Quote
 
 
 
 
Walter Roberson
Guest
Posts: n/a
 
      03-28-2007
In article < .com>,
<> wrote:
>I have a pix firewall(515 I believe) and every day at lunch and again
>at the end of the day the Inet slows to a crawl. It is obviously a
>user or group of users downloading a chunk of something. We have a
>full T1 and during work hours, it functions fine. I would like to get
>some software to possibly monitor the firewall and then point out the
>heaviest user's IP. I have been playing around with syslogd, but have
>not found a good way to cull through the log once it is written out.
>I also have tried sawmill, and while it is a step in the right
>direction, it is hard to believe there isn't a more direct way to
>figure it out.


There isn't a more direct way, at least not with PIX 6. (I'm not
familiar enough with PIX 7.)

> Any thoughts? I have the powers above ready to buy if
>I can find the right piece of software. thanks for your help.


There isn't really a lot of variety to choose from for PIX event
analysis. I had to write my own analysis software. There used
to be a commercial product, but it wasn't fast enough or flexible
enough for my needs... and now that product is no longer available
anyhow.

I supplied a simple perl program that might be good -enough- for
your purposes; see
http://groups.google.ca/group/comp.d...ddb0b6234c1e48
 
Reply With Quote
 
 
 
 
Scott Townsend
Guest
Posts: n/a
 
      03-28-2007
When we find out network is crawling I hook up the Ethernet cable from the
Router that connects to the internet to a old style HUB (not a switch) and
then a PC and the rest of the network on the Same HUB, then on the PC run a
IP Packet grabber on it. We use EtherPeek from WildPackets. It will show you
traffic and show you who is the biggest bandwidth or packet hog. EtherPeek
is great with all its charts and graphs, though you can run MS's Network
Monitor to look at the Traffic. You have to click the enable conversations
on the start page. I have not found a way to give Conversation stats. Just
shows you the Packets. If there is just one person generating the Traffic,
(in our case there was someone streaming video) it would be pretty obvious.

Scott<-


<> wrote in message
news: oups.com...
>I have a pix firewall(515 I believe) and every day at lunch and again
> at the end of the day the Inet slows to a crawl. It is obviously a
> user or group of users downloading a chunk of something. We have a
> full T1 and during work hours, it functions fine. I would like to get
> some software to possibly monitor the firewall and then point out the
> heaviest user's IP. I have been playing around with syslogd, but have
> not found a good way to cull through the log once it is written out.
> I also have tried sawmill, and while it is a step in the right
> direction, it is hard to believe there isn't a more direct way to
> figure it out. Any thoughts? I have the powers above ready to buy if
> I can find the right piece of software. thanks for your help.
>



 
Reply With Quote
 
Scott Townsend
Guest
Posts: n/a
 
      03-29-2007
Just downloaded a copy of Ethereal (GNU) and it has great Conversation
Statistics.
http://www.ethereal.com/

"Scott Townsend" <scott-i@.-N0-SPAMplease.enm.com> wrote in message
news:mZyOh.2915$ t...
> When we find out network is crawling I hook up the Ethernet cable from the
> Router that connects to the internet to a old style HUB (not a switch) and
> then a PC and the rest of the network on the Same HUB, then on the PC run
> a IP Packet grabber on it. We use EtherPeek from WildPackets. It will show
> you traffic and show you who is the biggest bandwidth or packet hog.
> EtherPeek is great with all its charts and graphs, though you can run MS's
> Network Monitor to look at the Traffic. You have to click the enable
> conversations on the start page. I have not found a way to give
> Conversation stats. Just shows you the Packets. If there is just one
> person generating the Traffic, (in our case there was someone streaming
> video) it would be pretty obvious.
>
> Scott<-
>
>
> <> wrote in message
> news: oups.com...
>>I have a pix firewall(515 I believe) and every day at lunch and again
>> at the end of the day the Inet slows to a crawl. It is obviously a
>> user or group of users downloading a chunk of something. We have a
>> full T1 and during work hours, it functions fine. I would like to get
>> some software to possibly monitor the firewall and then point out the
>> heaviest user's IP. I have been playing around with syslogd, but have
>> not found a good way to cull through the log once it is written out.
>> I also have tried sawmill, and while it is a step in the right
>> direction, it is hard to believe there isn't a more direct way to
>> figure it out. Any thoughts? I have the powers above ready to buy if
>> I can find the right piece of software. thanks for your help.
>>

>
>


 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Re: How include a large array? Edward A. Falk C Programming 1 04-04-2013 08:07 PM
Good example of how companies are abusing the DMCA Imhotep Computer Security 10 08-12-2005 09:36 PM
OT: Everyone report the birk abusing this newsgroup Carol A Computer Support 53 08-05-2005 02:32 AM
Netflix users: stop abusing those DVDs! K2 DVD Video 12 11-01-2003 05:50 PM
abusing and annoying mails Andrew Digital Photography 1 10-03-2003 06:18 AM



Advertisments
 



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57