How to monitor a endpoint for service/port traffic?

lytespeed
lytespeed Posts: 8  Freshman Member
First Comment Third Anniversary

Hello,

I was wondering how we would go about this. I have a client that I am auditing outbound traffic for (I am creating a security policy to prevent unapproved outbound traffic).

I would like to start by analyzing the outbound traffic and see what is currently being used. I can kind of do this by going to monitor→Traffic Statistics→Traffic Statistics. However, that only shows the top 20 and not all traffic that is outgoing. It also doesn't show what particular system this is tied to.

I know I can create a security policy and then log/log alert that policy. I need something more intuitive.

At the end of the day I am trying to monitor an endpoint to see all the outbound traffic on that device.

All Replies

  • PeterUK
    PeterUK Posts: 3,605  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary
    edited February 14

    Even if there was a 24hr monitor then you make rules to allow the traffic you could be allowing something you don't need to allow.

    What I do it just block everything LAN to WAN then start allowing ports, IP subnet or FQDN then look in the log for block traffic to see if its needed for something not working.

    What you might like is this idea on a given PC to link to the firewall giving you App level like control

    Virtual firewall link to USG/Zywall/VPN — Zyxel Community

  • lytespeed
    lytespeed Posts: 8  Freshman Member
    First Comment Third Anniversary

    Since this is a client (we are an MSP), I cannot create "trouble" for them by blocking ports randomly. I need some way to have a log of all the traffic from the endpoints so I can analyze the traffic and then update my LAN to WAN rule (I already have a rule in place for this, but I am trying to see if some of the older allowed services are still in use).

  • PeterUK
    PeterUK Posts: 3,605  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary

    I guess you can have a LAN to WAN log alert in allow then you get a Email or you packet capture with number of byes to capture say 100 then load wire shark a view traffic outgoing with port TCP or UDP to know what to allow

  • lytespeed
    lytespeed Posts: 8  Freshman Member
    First Comment Third Anniversary
    edited February 14

    I appreciate your suggestions PeterUK, but I am looking for something more definitive.

    For instance, it would be great to be able to setup a "rule" to monitor all traffic from a device at the firewall level. It seems kind of insane to me that something called a "Security Appliance" doesn't have this kind of capability.

    I mean I have created a security policy with log alert to do this in the past, but that isn't a good option just to get traffic information from an endpoint.

  • PeterUK
    PeterUK Posts: 3,605  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary
    edited February 14

    Not sure if nebula might have the answer

    But depending on what traffic is needed you can be faced with Apps that go full port range or even a App the has a fixed source port and random destination port which no USG model supports for a firewall rule to allow a given source port to any destination port.

  • Zyxel_Melen
    Zyxel_Melen Posts: 2,854  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate

    Hi @lytespeed,

    Nebula supports checking client's application in client page.

    Not sure if this meet your requirement. If you're interested, you can visit Nebula with a demo account when logging in.

    Zyxel Melen