Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Derek_Tom
New Contributor

LIVE MONITORING: What IPs using up most bandwidth right now?

Hi there,

I have a FortiGate 100D running v5.0, build4429 (GA).

In the Traffic History widget I can see my Internet connection saturated, inbound and/or outbound.

Users are complaining that Internet is very slow.

Top Sessions by Destination or Source Address widget shows current usage?

Top Clients by Bandwidth widget also shows me some info.

Is there a better way to try to determine live, at any time, what internal IPs are using up the most bandwidth and what hosts they are connected to?

Will a FortiAnalyzer help?

Are there better solutions outside of obtaining info from the FortiGate such as port mirroring on a switch to a Linux VM with special network monitoring software on it?

Ideally, I'd want a solution that can also email me alerts if there is any particular internal host that is utilizing excessive bandwidth. I'd like to know if the traffic is legitimate business traffic or from malware or for personal use.

Thanks in advance for any suggestions/feedback.

Cheers,

Derek

11 REPLIES 11
MBR
New Contributor III

Hi Mark/Derek,

 

The main issue is that offloaded traffic isn't counted. So it doesn't matter which tool you use to create reports and graphs. The base information is incomplete so you will never get 100% correct results.

- MBR -

NSE1, NSE2, NSE3

FGT60D/E, FWF60D/E, FGT200D

- MBR - NSE1, NSE2, NSE3 FGT60D/E, FWF60D/E, FGT200D
emnoc
Esteemed Contributor III

I have to disagree, the session tables statistics are pretty much spot-on & for all items that I've been monitoring. If in doubt and if you want to check, use a traffic generator and allow for the traffic to be passed by a specific policy. And then monitor the statistics and look and compare. Place the policy-id at the top of the sequence and conduct monitoring for that traffic. Test it with udp/tcp/icmp

 

bps

bytes sent

bytes received

 

 

e.g

 

diag sys sess filter policy 773

diag sys sess list

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Labels
Top Kudoed Authors