<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Finding bandwidth use by host in network to determine hosts infected with coinminer. in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Finding-bandwidth-use-by-host-in-network-to-determine-hosts/m-p/81082#M16385</link>
    <description>&lt;P&gt;Look into Logging and Monitoring Admin Guide, under Traffic Monitoring.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 07 Apr 2020 07:41:16 GMT</pubDate>
    <dc:creator>_Val_</dc:creator>
    <dc:date>2020-04-07T07:41:16Z</dc:date>
    <item>
      <title>Finding bandwidth use by host in network to determine hosts infected with coinminer.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Finding-bandwidth-use-by-host-in-network-to-determine-hosts/m-p/81052#M16374</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;I suddently see my bandwidth usage peak very high, after some analyze i think my users infected with coinminer. These users dont have endpoint security but they all access Internet through check point firewall. During working time, the banwitdh usage peak very high and when the users leave office it back to normal, that why i think user's devices is infected woth coinminer. And want to find which host using most bandwidth in network. I see in Log &amp;gt; View a bandwitdth report but when i click of that, it just empty and no data found. I also try with other reports but just the same :'no data found' or very least infor while there is a ton of logs.&lt;BR /&gt;Why there is many log but so very least in report ? Or can anyone please tell me is there any other way to find a list of top host using lot bandwitdh in network with Check oint firewall ?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 07 Apr 2020 01:09:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Finding-bandwidth-use-by-host-in-network-to-determine-hosts/m-p/81052#M16374</guid>
      <dc:creator>quanglnh</dc:creator>
      <dc:date>2020-04-07T01:09:51Z</dc:date>
    </item>
    <item>
      <title>Re: Finding bandwidth use by host in network to determine hosts infected with coinminer.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Finding-bandwidth-use-by-host-in-network-to-determine-hosts/m-p/81074#M16383</link>
      <description>&lt;P&gt;Which version are you running?&lt;/P&gt;</description>
      <pubDate>Tue, 07 Apr 2020 06:53:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Finding-bandwidth-use-by-host-in-network-to-determine-hosts/m-p/81074#M16383</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2020-04-07T06:53:00Z</dc:date>
    </item>
    <item>
      <title>Re: Finding bandwidth use by host in network to determine hosts infected with coinminer.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Finding-bandwidth-use-by-host-in-network-to-determine-hosts/m-p/81079#M16384</link>
      <description>&lt;P&gt;Hi Val,&lt;/P&gt;&lt;P&gt;I'm running R80.20&lt;/P&gt;</description>
      <pubDate>Tue, 07 Apr 2020 07:17:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Finding-bandwidth-use-by-host-in-network-to-determine-hosts/m-p/81079#M16384</guid>
      <dc:creator>quanglnh</dc:creator>
      <dc:date>2020-04-07T07:17:40Z</dc:date>
    </item>
    <item>
      <title>Re: Finding bandwidth use by host in network to determine hosts infected with coinminer.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Finding-bandwidth-use-by-host-in-network-to-determine-hosts/m-p/81082#M16385</link>
      <description>&lt;P&gt;Look into Logging and Monitoring Admin Guide, under Traffic Monitoring.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Apr 2020 07:41:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Finding-bandwidth-use-by-host-in-network-to-determine-hosts/m-p/81082#M16385</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2020-04-07T07:41:16Z</dc:date>
    </item>
    <item>
      <title>Re: Finding bandwidth use by host in network to determine hosts infected with coinminer.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Finding-bandwidth-use-by-host-in-network-to-determine-hosts/m-p/81084#M16386</link>
      <description>&lt;UL class="listbullet"&gt;
&lt;LI class="listbullet"&gt;authentication attempts to identify possible intrusion attempts.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="tpbodytext"&gt;A&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG class="menuoptions"&gt;Traffic&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;view can be created to monitor the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG class="menuoptions"&gt;Traffic&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;types listed in the following table.&lt;/P&gt;
&lt;TABLE class="tableintopic" border="0" width="582" cellspacing="0" cellpadding="2"&gt;
&lt;TBODY&gt;
&lt;TR align="left" valign="top"&gt;
&lt;TH bgcolor="#515254" width="108"&gt;
&lt;P class="tableheadingwhite"&gt;Traffic Type&lt;/P&gt;
&lt;/TH&gt;
&lt;TH bgcolor="#515254" width="474"&gt;
&lt;P class="tableheadingwhite"&gt;Explanation&lt;/P&gt;
&lt;/TH&gt;
&lt;/TR&gt;
&lt;TR align="left" valign="top"&gt;
&lt;TD width="108"&gt;
&lt;P class="tablebodytext"&gt;&lt;STRONG class="menuoptions"&gt;Services&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="474"&gt;
&lt;P class="tablebodytext"&gt;Shows the current status view about Services used through the selected gateway.&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR align="left" valign="top"&gt;
&lt;TD width="108" style="background-color: red;"&gt;
&lt;P class="tablebodytext"&gt;&lt;STRONG class="menuoptions"&gt;IPs/Network Objects&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="474" style="background-color: red;"&gt;
&lt;P class="tablebodytext"&gt;Shows the current status view about active IPs/Network Objects through the selected gateway.&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR align="left" valign="top"&gt;
&lt;TD width="108"&gt;
&lt;P class="tablebodytext"&gt;&lt;STRONG class="menuoptions"&gt;Security Rules&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="474"&gt;
&lt;P class="tablebodytext"&gt;Shows the current status view about the most frequently used Firewall rules.&lt;/P&gt;
&lt;P class="tablebodytext"&gt;The Name column in the legend states the rule number as previously configured in SmartConsole.&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR align="left" valign="top"&gt;
&lt;TD width="108"&gt;
&lt;P class="tablebodytext"&gt;&lt;STRONG class="menuoptions"&gt;Interfaces&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="474"&gt;
&lt;P class="tablebodytext"&gt;Shows the current status view about the Interfaces associated with the selected gateway.&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR align="left" valign="top"&gt;
&lt;TD width="108"&gt;
&lt;P class="tablebodytext"&gt;&lt;STRONG class="menuoptions"&gt;Connections&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="474"&gt;
&lt;P class="tablebodytext"&gt;Shows the current status view about current connections initiated through the selected gateway.&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR align="left" valign="top"&gt;
&lt;TD width="108"&gt;
&lt;P class="tablebodytext"&gt;&lt;STRONG class="menuoptions"&gt;Tunnels&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="474"&gt;
&lt;P class="tablebodytext"&gt;Shows the current status view about the Tunnels associated with the selected gateway and their usage.&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR align="left" valign="top"&gt;
&lt;TD width="108"&gt;
&lt;P class="tablebodytext"&gt;&lt;STRONG class="menuoptions"&gt;Virtual Link&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="474"&gt;
&lt;P class="tablebodytext"&gt;Shows the current traffic status view between two gateways (for example, Bandwidth, Bandwidth Loss, and Round Trip Time).&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR align="left" valign="top"&gt;
&lt;TD width="108"&gt;
&lt;P class="tablebodytext"&gt;&lt;STRONG class="menuoptions"&gt;Packet Size Distribution&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="474"&gt;
&lt;P class="tablebodytext"&gt;Shows the current status view about packets according to the size of the packets.&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR align="left" valign="top"&gt;
&lt;TD width="108"&gt;
&lt;P class="tablebodytext"&gt;&lt;STRONG class="menuoptions"&gt;QoS&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="474"&gt;
&lt;P class="tablebodytext"&gt;Shows the current traffic level for each QoS rule.&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R80.20_GA/WebAdminGuides/EN/CP_R80.20_LoggingAndMonitoring_AdminGuide/html_frameset.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R80.20_GA/WebAdminGuides/EN/CP_R80.20_LoggingAndMonitoring_AdminGuide/html_frameset.htm&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Apr 2020 07:45:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Finding-bandwidth-use-by-host-in-network-to-determine-hosts/m-p/81084#M16386</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2020-04-07T07:45:53Z</dc:date>
    </item>
  </channel>
</rss>

