Reports
The Traffic screen provides basic information about the following metrics:
- Most-visited Web sites and the number of times each one was visited. This count may not be accurate in some cases because the ZyWALL counts HTTP GET packets. Please see Maintenance > Report > Traffic for more information.
- Most-used protocols or service ports and the amount of traffic on each one
- LAN IP with heaviest traffic and how much traffic has been sent to and from each one
Note: The reporting may decrease the overall throughput through the ZyWALL.
You use the Traffic screen to tell the ZyWALL when to start and when to stop collecting information for these reports. You cannot schedule data collection; you have to start and stop it manually in the Traffic screen.
Maintenance > Report > Traffic
Label Description Data Collection Collect Statistics Select this to have the ZyWALL collect data for the report. If the ZyWALL has already been collecting data, the collection period displays to the right. The progress is not tracked here real-time, but you can click the Refresh button to update it. Apply Click Apply to save your changes back to the ZyWALL. Reset Click Reset to begin configuring this screen afresh. Traffics Interface Select the interface from which to collect information. You can collect information from Ethernet, VLAN, bridge, PPPoE/PPTP, and auxiliary interfaces. Traffic Type Select the type of report to display. Choices are:Host IP Address/User - displays the IP addresses or users with the most traffic and how much traffic has been sent to and from each one.Service/Port - displays the most-used protocols or service ports and the amount of traffic for each one.Web Site Hits - displays the most-visited Web sites and how many times each one has been visited.Each type of report has different information in the report (below). Refresh Click this button to update the report display. Flush Data Click this button to discard the report data for the selected interface and update the report display. These fields are available when the Report Type is Host IP Address/User. # This field is the rank of each record. The IP addresses and users are sorted by the amount of traffic. IP Address/User This field displays the IP address or user in this record. The maximum number of IP addresses or users in this report is indicated in Maximum Values for Reports. Direction This field indicates whether the IP address or user is sending or receiving traffic. Choices are Incoming and Outgoing.Incoming - traffic is coming from the IP address or user to the ZyWALL.Outgoing - traffic is going from the ZyWALL to the IP address or user. Amount This field displays how much traffic was sent or received from the indicated IP address or user. If the Direction is Incoming, a red bar is displayed; if the Direction is Outgoing, a blue bar is displayed. The unit of measure is bytes, Kbytes, Mbytes or Gbytes, depending on the amount of traffic for the particular IP address or user. The count starts over at zero if the number of bytes passes the byte count limit. See Maximum Values for Reports. These fields are available when the Report Type is Service/Port. # This field is the rank of each record. The protocols and service ports are sorted by the amount of traffic. Service/Port This field displays the protocol or service port in this record. The maximum number of protocols or service ports in this report is indicated in Maximum Values for Reports. Direction This field indicates whether the indicated protocol or service port is sending or receiving traffic. Choices are Incoming and Outgoing.Incoming - traffic is coming into the router through the interfaceOutgoing - traffic is going out from the router through the interface Amount This field displays how much traffic was sent or received from the indicated service / port. If the Direction is Incoming, a red bar is displayed; if the Direction is Outgoing, a blue bar is displayed. The unit of measure is bytes, Kbytes, Mbytes, Gbytes, or Tbytes, depending on the amount of traffic for the particular protocol or service port. The count starts over at zero if the number of bytes passes the byte count limit. See Maximum Values for Reports. These fields are available when the Report Type is Web Site Hits. # This field is the rank of each record. The domain names are sorted by the number of hits. Web Site This field displays the domain names most often visited. The ZyWALL counts each page viewed on a Web site as another hit. The maximum number of domain names in this report is indicated in Maximum Values for Reports. Hits This field displays how many hits the Web site received. The ZyWALL counts hits by counting HTTP GET packets. Many Web sites have HTTP GET references to other Web sites, and the ZyWALL counts these as hits too. The count starts over at zero if the number of hits passes the hit count limit. See Maximum Values for Reports.
The following table displays the maximum number of records shown in the report, the byte count limit, and the hit count limit.
Session Screen
The Session screen displays information about active sessions for debugging or statistical analysis. It is not possible to manage sessions in this screen. The following information is displayed.
You can look at all the active sessions by user or by service, or you can filter the information by user, protocol / service or service group, source address, and/or destination address and view it by user.
Anti-Virus Report
This screen displays anti-virus statistics.
IDP Report
This screen displays IDP (Intrusion Detection and Prevention) statistics.