Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
dirkdigs
New Contributor

somebody please xplain this to me

in my reports. i have 2 areas that dont add up. Bandwidth and Applications > Top Users by Bandwidth
11 REPLIES 11
dirkdigs
New Contributor

and Web Usage > Top Websites by Bandwidth
dirkdigs
New Contributor

there is no way in 1 week time that we have sent 800 GB to this top website. we only have a 5 down and 1 up DSL connection.
Warren_Olson_FTNT

This looks like time for a support ticket.
neonbit
Valued Contributor

+1 for support ticket. Also I' m reading the reports a little differently. From what I can see you' ve downloaded 800GB from the first server, not uploaded. Still 800GB+ download on a 5Mbps connection over one week is a little fishy. Are you sure that a) you' re report is configured for one week and only contains data from the one firewall and b) you don' t have a 100Mb fibre link connected that you' ve forgotten about? ;)
FatalHalt
Contributor II

Agreeing with Warren and neonbit, assuming the report is otherwise configured correctly, I would assume something' s up. I mean, even if you were able to fully saturate your line 24/7, that' s still like 1/3 of your available bandwidth for the week, lofty goal. Only other option I can figure out would be that this DNS name is actually internal somehow, and not actually crossing your DSL line.
Nihas
New Contributor

It might be a bug , I have the same in my new 5.2 . IPsec Traffics are showing as TB' s.... I have done #execute report recreate-db #execute report-config reset after the upgrade. But no luck. Any help before a TAC ticket??
Nihas [\b]
Nihas [\b]
Nihas
New Contributor

Any suggestion would be highly appreciated.
Nihas [\b]
Nihas [\b]
Istvan_Takacs_FTNT

I agree with Nihas, it appears to be a corrupted database. Not on FGT, but on FAZ something similar happened to us in the past and the solution was to rebuild the local DB. What version is your FGT? There might be a something similar going on as the FortiOS is the same across most of the products.
netmin
Contributor II

Same applies to our FGTs running 5.2. Additionally, the local report is randomly mixing local hostnames and ip-addresses. Recorded logs (scheduled upload to FAZ 5.0.7) appear to be correct.
Labels
Top Kudoed Authors