i want to monitor the egress interaface(tx) of the firewall and identify the users bandwidth, visited websites, who is having the most bandwidth for internet etc. i am planning to do this by port mirroring the port which is going to the firewall.
the mirrored port will be connected to the monitoring system, so that what ever tx traffic goes to the firewall goes to the monitored system.
Can anyone tell the best open source software that can do this. with graphs, user identification via IP address, the sites visted etc
If you have any cisco devices that support it, the devices can export NetFLow Data to a host PC. Very similiar to how it can send logging data to a syslog host. In this case, the netflow data can be analyzed in the fly by certain software to report on the data you want ( i.e. who is using the most traffic to visit a dancing cat video...).