Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ift38375
New Contributor

Monitor Users with live downloading from internet

Hello Experts,

 

I want to monitor those user who are downloading data/file from internet in office.

There are lots of option in UTM device but all are simply reports, reports are useful only for records.

I want to see User live http activity with Download data size ( like in MB,GB) so that i can check them realtime and stop her downloading same time. If user downloads huge data from internet ,Later I had to know, then it is of no use.

how can i do this from Fortigate 100D.

4 REPLIES 4
Adrian_Buckley_FTNT

What firmware version are you using and does your 100D have a Harddrive (not all do)?

ift38375

Adrian Buckley_FTNT wrote:

What firmware version are you using and does your 100D have a Harddrive (not all do)?

 

Hello,

 

Firmware Versionv5.2.1,build618  and no Harddrive... But This is not my Question's answer sir.

 

 

 

 

KS

ift38375

Please Experts help me out.....Otherwise we will go with other paid software like PRTG..and i do not want this.

 

 

Adrian_Lewis

Unless anyone knows better, most of the stats that you're likely to get are going to be based either on a session start log entry and a session close log entry. Only the close will give you the amount of data that was transmitted so you'd need to wait until the session is closed to work this out. This also doesn't help a lot with someone using bittorrent for example where there are loads of sessions but each one might not be using much bandwidth. I think that even the FortiView stuff in 5.2 suffers from the same limitations.

 

SNMP will only give you full bandwidth stats and not segmented by source IP or user. You can get the session list from SNMP as well but you'd need some impressive tools to get the mass of info into meaningful output.

 

Netflow/sFlow might be your best option as this can be set to send periodic stats while a data flow is in progress. Most tools that ingest Netflow will let you view a near-realtime view of traffic sorted by top-n fields such as top source IPs. It won't tell you the username but you could get the IP of the client and then work it out from there. There are a few free Netflow/sFlow tools available but it would involve additional software. PRTG is not exactly great with Netflow from memory as you have to define ports that you want to look at and it ignores everything else. Plixer have a free time-limited trial that keeps working with limited functionality but last time I tried it, there was a significant delay between what was happening and what was displayed - might have been my fault with the setup however. ManageEngine also have a free limited Netflow analysis product - can't comment on it's quality though.

 

If you're happy to learn a bit, you could try logstash/kibana/elasticsearch which can be configured to accept netflow data - it's very cool but take a bit more effort to set up.

 

Lastly but not leastly, there's http://www.fireplotter.com/ but I can't say if this will definitely give you what you need (might not handle the bittorrent example mentioned above for example). It does do realtime stats based (I think) on the CLI command diag sys session list. There a free trial and it's not much to buy either.

Labels
Top Kudoed Authors