Hi,
We have recently started using an XG450 (17.1.3 MR-3) and I have been noticing that in the Host section under reports the IP for the firewall (.40) always has the highest usage.
This is my first time using this appliance (and an in-house firewall) and I haven't really gotten used to the way the information is shown in the reports.
The thing that is throwing us off the most is that if i click on the IP the firewall is picking up the users that are generating the traffic. And if i go to the user i can see the traffic is always generated from two IPs the firewall and the user's laptop.
Is this the normal behavior and i am just misinterpreting the information in the reports? or is something wrong with the configuration?
The firewall is otherwise working ok, we have set it up in transparent mode with a LAN/WAN bridged interface and all filtering rules seem to be working as intended.
Thanks in advanced for the help
This thread was automatically locked due to age.