Jump to content


Photo

VPN traffic - where to look


  • Please log in to reply
3 replies to this topic

#1 JeWe

JeWe
  • Members
  • 96 posts
  • LocationGermany, NDS

Posted 13 May 2019 - 04:38 AM

Hi,

 

we are using a NGFW F400. I get weekly usage reports, it shows VPN usage, too. For one user, a large amount of data is reported (1,8GB). I can't see which user this is from default and I also can't see, what kind of traffic was produced. Where can I get this info?  Log?

 

Regards,

Jens

 



#2 Stefan Hora

Stefan Hora
  • Barracuda Guru
  • 142 posts

Posted 16 May 2019 - 09:50 AM

First check via Firewall/Monitor/Top 50 if the user is in the USER list and click on the User, then you can see the infos filtered for that user.

 

If the user is not in the Top 50 (select the proper Time Range (last hour....) then you may find some Info in statistics which per default goes back to 30 days:

Traffic Statistic Info is also under Statistics: Goto Server and select your Server, then your VPN-Service and then select Byte(Dst-Src).
Then select the Date in the left hand site and click on "Show".
Do you see any VPN Usernames as source ?

If not, look under VPN/Status via right-Click on the Username/Last Access what IP the User got in the VPN Clietn Subnet (Access Granted@.......)

 

And then look at above Statistics if you find the Source IP of the VPN-Client.



#3 JeWe

JeWe
  • Members
  • 96 posts
  • LocationGermany, NDS

Posted 17 May 2019 - 09:20 AM

Thanks for answering.

 

Sorry, should have said, that I'm searching for the traffic generated with the TINA client. So firewall monitor won't help me out. At least I think so.

 

>> Traffic Statistic Info is also under Statistics: Goto Server and select your Server, then your VPN-Service and then select Byte(Dst-Src).

>> Then select the Date in the left hand site and click on "Show".

Can't find this, what exactly do you mean?



#4 Stefan Hora

Stefan Hora
  • Barracuda Guru
  • 142 posts

Posted 17 May 2019 - 12:33 PM

The VPN-Service does not give you any information what the client did but the client has to pass the FW-Service before hitting your Lan and in the FW Service you have the detailed information WHAT the Tina VPN CLient did.
You only have to find out what virtual IP-Address the Tina VPN Client has used at that time, then you can search the FW Logs/Statistics with this ip address.

 

How to use the statistics is documented in the Barracuda Campus to display the firewall statistics.