Our ISPs router sends netflow data through our PIX to an inside machine to monitor bandwidth use.

When I spot a bandwidth hog (and I can only see the global addresses - src and dest - and port) I have to quickly telnet in to the PIX and do a...

pix# show xlate global | include 41998

When we run out of real world IPs, we use PAT on the .254 address.

That gives me the local IP for a PAT translation using port 41998. The problem is that the port number doesn't live forever and half the time I miss it.

Is there a program (or can I write a program) to poll the PIX either for a given global IP/port? What do I need to read?

Oh yeah, IOS 6.3.3

  1. You can set up logging to a server. Basically up the trap notification and get all traffic in and out. You can then search through the logs or watch the logs and grep for the information you want to see.

    Or just keep a connection open to the pix and "show log | inc
  2. Thanks.

    Just checking....

    I can turn on logging in the Pix and send the output to a server? Does it have to be a Windows Server server? Or will a workstation do?
