Intranet Reports - Firewall Reports


    The Intranet Reports section includes reports that show details of traffic transferred through the firewall by the internal hosts (hosts inside your LAN). In order to identify your internal hosts, you need to first configure your intranets by clicking the Intranet Settings link from the Settings > Firewall > Admin tab.

    The Top Internal Hosts (Sent+Received) graph shows the top internal hosts that are sending and receiving traffic through the firewall. You can expect only IP's inside your LAN here. The table below the graph shows the host/IP address, along with the number of hits, bytes received, bytes sent, and the total bytes (sent + received) of traffic generated.

    If you drill down any of the conversation, the conversation data is displayed in a pop up table with the following tabs:

    • Top Protocol Groups
    • Top Destinations
    • Top URLs Allowed
    • Top URLs Blocked
    • Rules Triggered

    Under each tab of analysis of traffic sent using a specific protocol, the following details are displayed.

    • Top Protocol Groups

    Protocol Group, Hits, Bytes received (MB), Bytes sent (MB), and Total Bytes (MB).

    • Top Destinations

    Destination, Protocol, Hits, Total Bytes (MB), and % Total Bytes.

    • Top URLs Allowed

    URL, Hits, % Hits, Total Bytes (MB), and %Total Bytes.

    • Top URLs Blocked

    URL and Hits.

    • Rules Triggered

    Rule Number/ID and Hits

    The Top Internal Protocol Groups (Sent+Received) graph shows the top protocol groups used by internal host for sending and receiving traffic through the firewall. The table below the graph shows the protocol group, along with the number of hits, % hits, total bytes of traffic generated and what % of traffic each protocol group constitute to the total traffic.

    If you drill down any of the conversation, the conversation data is displayed in a pop up table with the following tabs:

    • Top Protocol
    • Top Hosts
    • Top Destinations
    • Top Conversations.

    Under each tab of analysis of traffic sent using a specific protocol, the following details are displayed.

    • Top Protocol

    Protocol, Hits, Bytes Rcvd (MB), Bytes Sent (MB), Total Bytes (MB), and % Total Bytes.

    • Top Hosts

    Host, Hits, Bytes Rcvd (MB), Bytes Sent (MB), Total Bytes (MB), and % Total Bytes.

    • Top Destinations

    Destination, Hits, Total Bytes (MB) and % Total Bytes.

    • Top Conversations

    Host, Destination, Protocol, Hits, Bytes Rcvd (MB), Bytes Sent (MB), Total Bytes (MB), and % Total Bytes.

    The Top Internal Servers graph shows the top internal servers that served traffic. This is destination based report which list the internal servers which served more for external hosts. Transaction is not started/initiated by the servers listed here. Here you can expect all your server IPs which are behind your firewall, i.e. inside your LAN. The table below the graph shows the IP address of the internal server, along with the number of hits, the total bytes of traffic, and % of total traffic to the particular internal server.

    The Top Conversations table lists details like host which initiated the conversation, its destination, the protocol used for the conversation along with the number of hits, the total bytes of traffic generated and % of total traffic for the particular conversation.