Open for Voting

Cisco VPN bandwidth usage by user

I would like to see the ability to report bandwidth usage by the user account when connected via VPN.  When a user connects via VPN and browses the internet this traffic is not reported as being sourced from the VPN IP that the user was assigned, but by the firewalls outside interface IP.  This makes it impossible to know how much internet bandwidth this user used while connected to the VPN.  The username and source/destination IPs are reported in the firewalls syslog, so a way to correlate this information into a report would be very handy.

Thanks,

Abel

  • Darragh,

    We outsource our firewall monitoring and security to a third party so I've asked them for assistance on this issue since I've been pulled to some other projects and don't currently have the time.  Thanks for your time and suggestions.

    -Abel

  • Hi Abel,

    What if you were to use a SPAN port off the switch that the ASA connects to? You could use wireshark to check for the client IP addresses or it may show NAT addresses. Sounds like you need a data source inside the ASA

    Darragh

  • Darragh,

    Thanks for the reply, but after doing a little more digging this isn't actually what I need.  Here is what appears to be my real issue.  The daily NTA reports I have configured for Top 50 Endpoints are sometimes reporting my ASA's outside interface IP as the source/destination.  I'm trying to figure out what the actual internal and/or vpn source IP is so I can figure out who/what is using all this bandwidth.  Since the firewall's IP is all I'm seeing (besides the outside server IP) I'm unable to track this down.  Any thoughts?

    -Abel

  • Hi Abel,

    When the user authenticates on the network do you have events on the Windows domain controllers with the users client IP?

    Darragh