cancel
Showing results for 
Search instead for 
Did you mean: 
Create Post

Cisco VPN bandwidth usage by user

Cisco VPN bandwidth usage by user

I would like to see the ability to report bandwidth usage by the user account when connected via VPN.  When a user connects via VPN and browses the internet this traffic is not reported as being sourced from the VPN IP that the user was assigned, but by the firewalls outside interface IP.  This makes it impossible to know how much internet bandwidth this user used while connected to the VPN.  The username and source/destination IPs are reported in the firewalls syslog, so a way to correlate this information into a report would be very handy.

Thanks,

Abel

10 Comments

Hi Abel,

When the user authenticates on the network do you have events on the Windows domain controllers with the users client IP?

Darragh

Level 7

Darragh,

Thanks for the reply, but after doing a little more digging this isn't actually what I need.  Here is what appears to be my real issue.  The daily NTA reports I have configured for Top 50 Endpoints are sometimes reporting my ASA's outside interface IP as the source/destination.  I'm trying to figure out what the actual internal and/or vpn source IP is so I can figure out who/what is using all this bandwidth.  Since the firewall's IP is all I'm seeing (besides the outside server IP) I'm unable to track this down.  Any thoughts?

-Abel

Hi Abel,

What if you were to use a SPAN port off the switch that the ASA connects to? You could use wireshark to check for the client IP addresses or it may show NAT addresses. Sounds like you need a data source inside the ASA

Darragh

Level 7

Darragh,

We outsource our firewall monitoring and security to a third party so I've asked them for assistance on this issue since I've been pulled to some other projects and don't currently have the time.  Thanks for your time and suggestions.

-Abel

Level 15

That's a tough one. A lot of times the addresses are using NAT and how do you easily map the internal to external address for your reports? If anyone has any ideas I would love to hear them because I run into the time.

Cisco ASA's provide bandwidth consumed per username; it's displayed easily in ASDM.

One would hope Solarwinds NPM could access this info and present it in views, and leverage it to create reports.

Level 12

I created a quick and easy widget for my ASA pages. It'll give you the top talkers right away. Just select your VPN devices as your data sources.

SW VPN Users Widget.jpeg

I followed your instructions--they worked perfectly, and on the first attempt.  Nicely done!

Thank you for sharing.

Rick Schroeder

Community Manager
Community Manager
Status changed to: Open for Voting
 
Level 7

What steps did you take to get this information?

I'm using NTA HF1 2019.4 -  I can not see where to add this.
@bmallon 

@rschroeder 

Thank you

Euan