SecuRepoter - Traffic analyses

Options
Rösti
Rösti Posts: 15 image  Freshman Member
First Comment Friend Collector

I use SecuReporter on my site. In Analysis - Traffic, sections Top Source Hostname and Top Source MAC Address are always empty. while other information is present. All checkboxes in Log&Report-SecuReporter of the FW appliance are ticked. Why so?

Accepted Solution

  • Zyxel_Judy
    Zyxel_Judy Posts: 2,626 image  Zyxel Employee
    Zyxel Certified Network Engineer Level 2 - Nebula Zyxel Certified Network Engineer Level 2 - Switch Zyxel Certified Network Engineer Level 2 - Security Zyxel Certified Network Engineer Level 1 - Nebula
    edited May 22 Answer ✓
    Options

    Hi @Rösti ,

    To reduce CPU load, client log reporting to SecuReporter (including top hostnames, MAC addresses, etc.) is currently disabled by default.
    If you need this feature right away, it can be re-enabled via CLI.

    usgflex700h# edit running
    usgflex700h running config# vrf main secureporter traffic-log client-info enabled true
    usgflex700h running config# commit
    Configuration committed.
    usgflex700h running config# exit
    usgflex700h> copy running startup
    Overwrite startup configuration? [y/N] y

    This will no longer be necessary from version 1.39 onwards — with improved CPU optimization in that release, client log reporting will be enabled by default again.

    By the way, please enable Device Insight as well

    image.png

    Zyxel_Judy

All Replies

  • Zyxel_Judy
    Zyxel_Judy Posts: 2,626 image  Zyxel Employee
    Zyxel Certified Network Engineer Level 2 - Nebula Zyxel Certified Network Engineer Level 2 - Switch Zyxel Certified Network Engineer Level 2 - Security Zyxel Certified Network Engineer Level 1 - Nebula
    Options

    Hi @Rösti ,

    To better assist you, could you please share your Nebula organization and site name? Additionally, please ensure that Zyxel Support access is enabled.

    Zyxel_Judy

  • Zyxel_Judy
    Zyxel_Judy Posts: 2,626 image  Zyxel Employee
    Zyxel Certified Network Engineer Level 2 - Nebula Zyxel Certified Network Engineer Level 2 - Switch Zyxel Certified Network Engineer Level 2 - Security Zyxel Certified Network Engineer Level 1 - Nebula
    edited May 22 Answer ✓
    Options

    Hi @Rösti ,

    To reduce CPU load, client log reporting to SecuReporter (including top hostnames, MAC addresses, etc.) is currently disabled by default.
    If you need this feature right away, it can be re-enabled via CLI.

    usgflex700h# edit running
    usgflex700h running config# vrf main secureporter traffic-log client-info enabled true
    usgflex700h running config# commit
    Configuration committed.
    usgflex700h running config# exit
    usgflex700h> copy running startup
    Overwrite startup configuration? [y/N] y

    This will no longer be necessary from version 1.39 onwards — with improved CPU optimization in that release, client log reporting will be enabled by default again.

    By the way, please enable Device Insight as well

    image.png

    Zyxel_Judy