Screen OS

last person joined: 8 months ago 

This is a legacy community with limited Juniper monitoring.
  • 1.  How to find out the IPs that are consuming Internet Bandwidth

    Posted 10-17-2013 07:39

    Hi,

     

    I have a SSG140 firewall and I would like to know a method by wich I can find out the IPs(hosts) in my internal network that are consuming Internet bandwidth.

    Is there a way to find it in real time? Is there a way to create a NSM report for it? Where can I find an example?

     

    Thank you for your answers.

     

    TCP.



  • 2.  RE: How to find out the IPs that are consuming Internet Bandwidth

     
    Posted 10-23-2013 04:04

    Hi,

     

    There is no such feature available on SSG to find out which IPs are consuming Internet BW.

     

    Regards,

    Sarab



  • 3.  RE: How to find out the IPs that are consuming Internet Bandwidth
    Best Answer

     
    Posted 10-23-2013 06:30

    Hello.

     

    Unfortunately, ScreenOS has no netflow.  Your best bet will be to parse the syslog traffic logs, which includes bytes sent/received for each session.

     

    I believe you posted a question on how to do this in NSM... i believe that would be easiest (or splunk...)

     

    One thing to keep in mind is that the bytes sent/received are only recorded when a session is closed.  So if there is a long lasting session that lasts for days... these won't be reflected in the report.

     

    Hope this helps.

     

    Regards,

    Sam



  • 4.  RE: How to find out the IPs that are consuming Internet Bandwidth

    Posted 10-24-2013 02:07

    Hi,

     

    Thank you for your answer it helped me a lot.

    By the way the Log on Session-init is necessary for this or not.

     

    Regards.

     



  • 5.  RE: How to find out the IPs that are consuming Internet Bandwidth

     
    Posted 10-24-2013 06:00

    Hello.

     

    No, session-init is not a requirement.

     

    session-close also has a field showing the 'elapsed' time, so if needed, you can backtrack how long the session was active.

     

    Hope this helps.

     

    Regards,

    Sam