Yesterday, we seemed to get hit by a very large amount of traffic externally.
When I looked at the dashboard, the WAN was at 100% of our bandwidth and the LANS, DMZ's were trickling along with normal traffic.
Now when somebody is downloading/uploading, you can see that the LAN's/DMZ's would be up and sometime match exactly. But this time it wasn't which meant that nobody was downloading/uploading.
But clicking on the WAN and digging into it did not really reveal much either eg multiple ip's being connected by one didn't exactly stand out from the others.
So what could it be? A large email going to the proxy? A DDOS? Anybody know how to get the UTM to reveal this information in real time?
This thread was automatically locked due to age.