The traffic doesn't match the real traffic

The traffic doesn't match the real traffic


Dear All
 
I have Firewall analyzer 6. The problem is that from the Firewall reports top hosts I can see the sent is 0 bytes and the recieved is (too much huge).
 
1- How can recieved this much traffic without sending any bytes?
2- How the firewall analyzer tracking the traffic?
3- I have Cisco FWSM. I enabled the logging like the document. Do I have to enable the logging with each line of the access-list to log all the traffic and anlyze it by the firewall analyzer or the firewall analyzer needs only the logging configuration on the FA document.
 
Also I can see one IP on the top hosts having total traffic (100 MB) + hit counts (100), the same IP I can found it in the top conversation haing conversation with one host with total traffic (100.95 MB) + hit counts (117).
 
Any help is appreciated,
 
Thanks,
 
 

                New to ADSelfService Plus?