<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Internet content filtering solutions for business - WFilter Blog &#187; How to monitor internet usage</title>
	<atom:link href="http://blog.wfilterngf.com/?cat=25&#038;feed=rss2" rel="self" type="application/rss+xml" />
	<link>http://blog.wfilterngf.com</link>
	<description>Internet content filter and firewall solutions for business network.</description>
	<lastBuildDate>Thu, 28 Aug 2025 05:37:57 +0000</lastBuildDate>
	<language>en-US</language>
		<sy:updatePeriod>hourly</sy:updatePeriod>
		<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.8.5</generator>
	<item>
		<title>Monitor network bandwidth with cisco switch.</title>
		<link>http://blog.wfilterngf.com/?p=417</link>
		<comments>http://blog.wfilterngf.com/?p=417#comments</comments>
		<pubDate>Fri, 05 May 2017 08:51:33 +0000</pubDate>
		<dc:creator><![CDATA[WFilter]]></dc:creator>
				<category><![CDATA[bandwidth]]></category>
		<category><![CDATA[How to monitor internet bandwidth]]></category>
		<category><![CDATA[How to monitor internet usage]]></category>
		<category><![CDATA[Internet monitor]]></category>

		<guid isPermaLink="false">http://blog.wfilterros.com/?p=417</guid>
		<description><![CDATA[In this post, I will bring you a bandwidth monitoring solution based on your cisco switch. In case your router/firewall does not have bandwidth monitoring features, or you need more detailed reports, this solution can help you. First, the network topology diagram: &#160; Most cisco switch supports &#8220;port mirroring(SPAN)&#8221; feature. You may use below commands [&#8230;]]]></description>
				<content:encoded><![CDATA[<p>In this post, I will bring you a bandwidth monitoring solution based on your cisco switch. In case your router/firewall does not have bandwidth monitoring features, or you need more detailed reports, this solution can help you.</p>
<p>First, the network topology diagram:<br />
<a href="http://blog.wfilterngf.com/wp-content/uploads/2017/04/cisco1.png"><img class="alignnone  wp-image-408" alt="cisco1" src="http://blog.wfilterngf.com/wp-content/uploads/2017/04/cisco1.png" width="615" height="232" /></a></p>
<p>&nbsp;</p>
<p>Most cisco switch supports &#8220;port mirroring(SPAN)&#8221; feature. You may use below commands to enable it:</p>
<p>1. Set source port</p>
<p>Switch(config)#monitor session 1 source interface Fa0/23</p>
<p>2. Set target port</p>
<p>Switch(config)#monitor session 1 destination interface Fa0/22 ingress vlan 1</p>
<p>Then, you need to install a passby filtering program(ie: <a href="http://www.wfiltericf.com/WFilter.htm" target="_blank">WFilter internet content filter</a>) in a windows PC, and connect this PC to the &#8220;target port&#8221;. So you can monitor internet bandwidth and live connections of network clients.</p>
<p>The new diagram:</p>
<p><a href="http://blog.wfilterngf.com/wp-content/uploads/2017/04/cisco2.png"><img class="alignnone size-full wp-image-409" alt="cisco2" src="http://blog.wfilterngf.com/wp-content/uploads/2017/04/cisco2.png" width="600" /></a></p>
<p>Now let&#8217;s check what you can monitor with WFilter:<br />
1. Clients List</p>
<p><img alt="" src="http://www.wfiltericf.com/internet-usage-monitoring/images/internet_usage_monitoring02.jpg" /></p>
<p>2. Live Connections</p>
<p><img alt="" src="http://www.wfiltericf.com/internet-usage-monitoring/images/internet_usage_monitoring05.jpg" /></p>
<p>3. Bandwidth Reports</p>
<p><a href="http://blog.wfilterngf.com/wp-content/uploads/2017/05/QQ截图20170505164907.png"><img class="alignnone size-full wp-image-418" alt="QQ截图20170505164907" src="http://blog.wfilterngf.com/wp-content/uploads/2017/05/QQ截图20170505164907.png" width="1205" height="697" /></a></p>
<p><a href="http://blog.wfilterngf.com/wp-content/uploads/2017/05/QQ截图20170505164940.png"><img class="alignnone size-full wp-image-419" alt="QQ截图20170505164940" src="http://blog.wfilterngf.com/wp-content/uploads/2017/05/QQ截图20170505164940.png" width="1208" height="665" /></a></p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.wfilterngf.com/?feed=rss2&#038;p=417</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to monitor wireless users in network with WFilter?</title>
		<link>http://blog.wfilterngf.com/?p=151</link>
		<comments>http://blog.wfilterngf.com/?p=151#comments</comments>
		<pubDate>Tue, 27 May 2014 09:06:52 +0000</pubDate>
		<dc:creator><![CDATA[WFilter]]></dc:creator>
				<category><![CDATA[How to monitor internet usage]]></category>
		<category><![CDATA[Internet monitor]]></category>
		<category><![CDATA[monitor wireless users]]></category>

		<guid isPermaLink="false">http://blog.imfirewall.us/How+To+Monitor+Wireless+Users+In+Network+With+WFilter.aspx</guid>
		<description><![CDATA[Since most wireless devices obtain IP addresses dynamically, management of wireless devices has become a challenge to network administrators. It’s not easy to identify wireless devices by IP addresses or MAC addresses. However, with WFilter, you can identify wireless devices by users. When enabled, mobile users need to authenticate themselves to access internet. Both active [&#8230;]]]></description>
				<content:encoded><![CDATA[<p>Since most wireless devices obtain IP addresses dynamically, management of wireless devices has become a challenge to network administrators. It’s not easy to identify wireless devices by IP addresses or MAC addresses. However, with WFilter, you can identify wireless devices by users.</p>
<p>When enabled, mobile users need to authenticate themselves to access internet. Both active directly authentication and WFilter local authentication are supported. Then you can check devices and users in WFilter console in a few clicks.</p>
<p>In this example, I will guide you to enable AD account monitoring for wireless devices.</p>
<h1>1.Enable Domain account monitoring</h1>
<p>In &#8220;Account Monitoring &#8220;, choose “Windows Active Directory”, click “Enabled”, add a Domain Controller.</p>
<p><img border="0" src="http://blog.wfilterngf.com/content/binary/MADaccount001.jpg"></p>
<h1>2.Advanced Settings</h1>
<p> Click “Advanced Settings”, choose “Require web authentication for devices which do not log into the domain”, Save Settings. You also can choose “Block all internet access when web authentication is required”and “Require re-authentication when an user has no internet activity for 30 minute(s)”.</p>
<p><img border="0" src="http://blog.wfilterngf.com/content/binary/MADaccount002.jpg"></p>
<h1>3.Web authentication </h1>
<p> Users will not be able to access internet until they’re authenticated. When user authentication web page will show up when browser is open as shown in below figure.</p>
<p><img border="0" src="http://blog.wfilterngf.com/content/binary/MADaccount003.jpg"></p>
<h1>4.Online Users</h1>
<p>In WFilter’s “Online Users”, you can get a list of online devices and users.</p>
<p><img border="0" src="http://blog.wfilterngf.com/content/binary/MADaccount004.jpg"></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.wfilterngf.com/?feed=rss2&#038;p=151</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to push web pages to network clients with Wfilter ?</title>
		<link>http://blog.wfilterngf.com/?p=153</link>
		<comments>http://blog.wfilterngf.com/?p=153#comments</comments>
		<pubDate>Mon, 14 Apr 2014 02:32:21 +0000</pubDate>
		<dc:creator><![CDATA[WFilter]]></dc:creator>
				<category><![CDATA[How to monitor internet usage]]></category>
		<category><![CDATA[Internet monitor]]></category>

		<guid isPermaLink="false">http://blog.imfirewall.us/How+To+Push+Web+Pages+To+Network+Clients+With+Wfilter.aspx</guid>
		<description><![CDATA[In WFilter 4.1 version,a new feature named &#8220;web content pushing&#8221; is added. This feature enables you to push a web page to client devices at a time interval. You can define time interval, triggers for pushing and pushing pages. In this example, I will guide you to use the &#8220;web content pushing&#8221;in WFilter 4.1. 1.Wfilter [&#8230;]]]></description>
				<content:encoded><![CDATA[<p> In WFilter 4.1 version,a new feature named &#8220;web content pushing&#8221; is added. This feature enables you to push a web page to client devices at a time interval. You can define time interval, triggers for pushing and pushing pages.</p>
<p>In this example, I will guide you to use the &#8220;web content pushing&#8221;in WFilter 4.1.</p>
<h1>1.Wfilter Settings</h1>
<p>1.1New a blocking level</p>
<p><img border="0" src="http://blog.wfilterngf.com/content/binary/图片1[1].jpg"></p>
<p>Add  a &#8220;company broadcast&#8221; policy in &#8220;Policy Settings&#8221;->&#8221;Blocking Level Settings&#8221;. Check &#8220;Enable Web Content Pushing&#8221; and click &#8220;New&#8221;.</p>
<p><img border="0" src="http://blog.wfilterngf.com/content/binary/图片2[1].jpg"></p>
<p>Add a new &#8220;web content pushing&#8221; named &#8220;broadcast&#8221;, in &#8220;Triggers&#8221;, input &#8220;www.baidu.com&#8221; which means this web pushing shall be triggered when baidu.com is visited.</p>
<p>In &#8220;Content&#8221;, you can put anything you want to broadcast. It will be displayed when triggered.</p>
<p><img border="0" src="http://blog.wfilterngf.com/content/binary/图片3[1].jpg"></p>
<p>Apply this blocking policy to target ip ranges.</p>
<p><img border="0" src="http://blog.wfilterngf.com/content/binary/图片4[1].jpg"></p>
<p>1.2 When an user visits baidu.com, the broadcast message will show up every ten minutes.</p>
<p><img border="0" src="http://blog.wfilterngf.com/content/binary/图片5[1].jpg"></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.wfilterngf.com/?feed=rss2&#038;p=153</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to monitor and filter internet activities of PPPOE users?</title>
		<link>http://blog.wfilterngf.com/?p=164</link>
		<comments>http://blog.wfilterngf.com/?p=164#comments</comments>
		<pubDate>Tue, 02 Jul 2013 06:13:03 +0000</pubDate>
		<dc:creator><![CDATA[WFilter]]></dc:creator>
				<category><![CDATA[Block Messenger]]></category>
		<category><![CDATA[Chat Monitor]]></category>
		<category><![CDATA[Content Filter]]></category>
		<category><![CDATA[How to block internet]]></category>
		<category><![CDATA[How to filter internet access]]></category>
		<category><![CDATA[How to monitor internet bandwidth]]></category>
		<category><![CDATA[How to monitor internet usage]]></category>
		<category><![CDATA[Internet Monitoring]]></category>

		<guid isPermaLink="false">http://blog.imfirewall.us/How+To+Monitor+And+Filter+Internet+Activities+Of+PPPOE+Users.aspx</guid>
		<description><![CDATA[PPPOE is widely used for user authentication and traffic accounting. However, it&#8217;s a little difficult to monitor and filter PPPOE clients&#8217; internet usage and behavior. In this example, we will demonstrate you to monitor and filter PPPOE clients with WFilter Free. Please notice that only non-encrypted and uncompressed PPPOE traffic can be supported. So the [&#8230;]]]></description>
				<content:encoded><![CDATA[<p>PPPOE is widely used for user authentication and traffic accounting. However, it&#8217;s a little difficult to monitor and filter PPPOE clients&#8217; internet usage and behavior. </p>
<p>In this example, we will demonstrate you to monitor and filter PPPOE clients with WFilter Free. Please notice that only non-encrypted and uncompressed PPPOE traffic can be supported. So the first step is to configure your PPPOE server for non-encryption and non-compression.</p>
<h2>1. PPPOE server settings</h2>
<p>Let&#8217;s take windows 2003 and RouteOS for examples.</p>
<h4>1). 2003 Server Configuration</h4>
<p>If you are using windows 2003 server as the PPPOE server, please follow below steps to configure:</p>
<p>In &#8220;Properties&#8221; of the &#8220;Routing and Remote Access&#8221;, disable &#8220;software compression&#8221; and &#8220;LCP&#8221; in the &#8220;PPP&#8221; tab.</p>
<p><img src="http://blog.wfilterngf.com/content/binary/PPPOE_en_01.png" border="0"></p>
<p>Edit &#8220;remote access policy&#8221; for &#8220;no encryption&#8221; in &#8220;Edit Profile&#8221;. <font color="#FF0000">Notice: The default two policies shall all be modified.</font></p>
<p><img src="http://blog.wfilterngf.com/content/binary/PPPOE_en_02.png" border="0"><br />
<br />
<img src="http://blog.wfilterngf.com/content/binary/PPPOE_en_03.png" border="0"></p>
<h4>2). ROS Configuration</h4>
<p>If you are using routeOS as PPPOE server, please follow these steps to disable compression and encryption:</p>
<p>In &#8220;PPP&#8221; tab of &#8220;Profiles&#8221;, click &#8220;Protocols&#8221; and disable compression and encryption.</p>
<p><img src="http://blog.wfilterngf.com/content/binary/PPPOE_ZH_24.png" border="0"></p>
<h2>2. Monitor PPPOE clients in WFilter</h2>
<h3>2.1) Choose the internal adapter</h3>
<p>Now WFilter is able to parse PPPOE traffic. In this example, we just install WFilter free in the windows 2003 PPPOE server.</p>
<p>You need to choose the internal adapter as the &#8220;monitoring adapter&#8221; in &#8220;System Settings&#8221;-&gt;&#8221;Monitoring Settings&#8221; of WFilter.</p>
<p><img src="http://blog.wfilterngf.com/content/binary/PPPOE_en_04.png" border="0"><br />
<img src="http://blog.wfilterngf.com/content/binary/PPPOE_en_05.png" border="0"></p>
<h3>2.2). Setup client policy</h3>
<p>Add a block policy to block web surfing.</p>
<p><img src="http://blog.wfilterngf.com/content/binary/PPPOE_en_06.png" border="0"><br />
<img src="http://blog.wfilterngf.com/content/binary/PPPOE_en_07.png" border="0"></p>
<p>Apply this policy to PPPOE clients&#8217; ip ranges</p>
<p><img src="http://blog.wfilterngf.com/content/binary/PPPOE_en_08.png" border="0"><br />
<img src="http://blog.wfilterngf.com/content/binary/PPPOE_en_09.png" border="0"></p>
<h3>2.3). Check Blocking</h3>
<p>PPPOE clients get blocked.</p>
<p><img src="http://blog.wfilterngf.com/content/binary/PPPOE_en_10.png" border="0"></p>
<p>Blocking events in WFilter.</p>
<p><img src="http://blog.wfilterngf.com/content/binary/PPPOE_en_11.png" border="0"></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.wfilterngf.com/?feed=rss2&#038;p=164</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Wifi network monitoring solutions</title>
		<link>http://blog.wfilterngf.com/?p=166</link>
		<comments>http://blog.wfilterngf.com/?p=166#comments</comments>
		<pubDate>Thu, 13 Jun 2013 06:20:19 +0000</pubDate>
		<dc:creator><![CDATA[WFilter]]></dc:creator>
				<category><![CDATA[Deployment]]></category>
		<category><![CDATA[How to monitor internet usage]]></category>

		<guid isPermaLink="false">http://blog.imfirewall.us/Wifi+Network+Monitoring+Solutions.aspx</guid>
		<description><![CDATA[Since most wireless network cards do not support &#8220;promiscuous mode&#8221;, it becomes complicated to deploy internet monitoring and filtering in a wifi network. In this blog, I will list three common solutions for wifi network monitoring. 1. Port mirroring Some wireless router can support &#8220;port mirroring&#8221; feature. If your router support this feature, you can [&#8230;]]]></description>
				<content:encoded><![CDATA[<p>Since most wireless network cards do not support &#8220;promiscuous mode&#8221;, it becomes complicated to deploy internet monitoring and filtering in a wifi network.</p>
<p>In this blog, I will list three common solutions for wifi network monitoring.</p>
<h1>1. Port mirroring</h1>
<p>Some wireless router can support &#8220;port mirroring&#8221; feature. If your router support this feature, you can enable the mirroring port and connect the WFilter computer to the mirroring port. The WFilter computer shall have a wired network card can be connected to the mirroring port by a cable.</p>
<p>This cisco article provides a good guide: <a href="http://sbkb.cisco.com/CiscoSB/GetArticle.aspx?docid=bd5aaaffbaa34e5f9b8b8fde1475bae8_Configuration_of_Port_Mirroring_on_WRVS4400N_Wireless_N_Giga.xml&amp;pid=2&amp;converted=0" target="_blank">Configuration of Port Mirroring on WRVS4400N Wireless-N Gigabit Security Router</a></p>
<h1>2. Deploy WFilter in an upper layer device</h1>
<p>In case you have an upper layer device with &#8220;port mirroring&#8221; feature, you can deploy WFilter in the upper layer. Check this solution: <a href="http://www.wfiltericf.com/support/WFilter_4_0/Doc/deploy_wireless.htm" target="_blank">WFilter deployment in a wireless network</a>
</p>
<h1>3. Configure the WFilter PC as internet gateway.</h1>
<p>This solution is helpful when you only have ONE wireless router in your network, it&#8217;s rather simple for WFilter deployment. This solution rather helps when you don&#8217;t have a port mirroring switch or router. </p>
<p>Check this solution at here: <a href="http://blog.wfilterngf.com/A+Simple+Deployment+Of+WFilter+With+Wireless+Router.aspx">A simple deployment of WFilter with wireless router</a>
</p>
<h1>4. Turn your PC into a Wi-Fi HotSpot to deploy WFilter</h1>
<p>You can turn your windows PC into a wifi hotspot, so clients connected to this wifi hotspot can be monitored by WFilter.</p>
<p>Check this solution at here: <a href="http://blog.wfilterngf.com/Turn+Your+PC+Into+A+WiFi+HotSpot+To+Deploy+WFilter+Internet+Monitoring.aspx">Turn your PC into a Wi-Fi HotSpot to deploy WFilter</a>
</p>
<h1>5. Reflash your router into an embeded linux system.</h1>
<p>If none of above solutions works for you, you can choose to reflash your router into openwrt/ddwrt/tomato/gargoyle firmware. These firmware allows you to install software port-mirroring solutions. </p>
<p>Here is a guide: <a href="http://blog.wfilterngf.com/WFilter+Deployment+With+Openwrt+Router.aspx" target="_blank">WFilter deployment with openwrt router.</a> </p>
<p>&nbsp;</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.wfilterngf.com/?feed=rss2&#038;p=166</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WFilter deployment with gargoyle router.</title>
		<link>http://blog.wfilterngf.com/?p=168</link>
		<comments>http://blog.wfilterngf.com/?p=168#comments</comments>
		<pubDate>Wed, 22 May 2013 04:46:09 +0000</pubDate>
		<dc:creator><![CDATA[WFilter]]></dc:creator>
				<category><![CDATA[Content Filter]]></category>
		<category><![CDATA[Deployment]]></category>
		<category><![CDATA[How to monitor internet usage]]></category>
		<category><![CDATA[Internet Monitoring]]></category>

		<guid isPermaLink="false">http://blog.imfirewall.us/WFilter+Deployment+With+Gargoyle+Router.aspx</guid>
		<description><![CDATA[1. Gargoyle Router Introduction Gargoyle is an OpenWrt distribution which aims to be easy to use through a simplified Web interface. Gargoyle can extend your wireless router into a powerful Linux system. even if your router hardware does not support &#8220;port mirroring&#8221; function, you can also enable traffic mirroring by software mirroring. This blog will [&#8230;]]]></description>
				<content:encoded><![CDATA[<h2>1. Gargoyle Router Introduction</h2>
<p>Gargoyle is an OpenWrt distribution which aims to be easy to use through a simplified Web interface. Gargoyle can extend your wireless router into a powerful Linux system. even if your router hardware does not support &#8220;port mirroring&#8221; function, you can also enable traffic mirroring by software mirroring.</p>
<p>This blog will guide you to install &#8220;port-mirroring&#8221; program in your Gargoyle router and deploy WFilter for internet monitoring and filtering. We assume you already has an Gargoyle router, if not, please check <a href="http://www.gargoyle-router.com/">Gargoyle homepage</a> to get the latest firmware.</p>
<h2>2. Port-mirroring program</h2>
<p>Port-mirroring is an open source project sponsored by <a href="http://www.wfiltericf.com/">IMFirewall Software</a>, it is designed to mirror network traffic on linux systems.</p>
<h3>2.1. Installation</h3>
<p>For detailed installation guide, please check <a href="http://code.google.com/p/port-mirroring/">Port-mirroring open source packet mirroring.</a> In this guide, let&#8217;s take linksys wrt54g router as an example.</p>
<p></p>
<p><b><font color="#000000">Steps:</font></b></p>
<p>a). opkg update.
</p>
<p>b). opkg install http://port-mirroring.googlecode.com/files/port-mirroring_1.3-1_12.09_brcm47xx.ipk</p>
<p><img src="http://blog.wfilterngf.com/content/binary/Gargoyle ___002.jpg" border="0"></p>
<p>Because gargoyle is based on openwrt attitude adjustment 12.09 branch, we need to install the build for openwrt 12.09.</p>
<h3>2.2. Configuration</h3>
<p>You need to edit /etc/config/port-mirroring to set the mirroring target and mirrored source interfaces.</p>
<p>In this example, we choose &#8220;eth0&#8243; wireless adapter as the mirrored source interface.</p>
<p><img src="http://blog.wfilterngf.com/content/binary/Gargoyle ___003.jpg" border="0"></p>
<h3>2.3. Start Port-mirroring</h3>
<p>/etc/init.d/port-mirroring start</p>
<p><img src="http://blog.wfilterngf.com/content/binary/Gargoyle ___004.jpg" border="0"></p>
<h2>3. Check monitoring in WFilter</h2>
<p>Now WFilter shall be able to monitor client computers.</p>
<p><img src="http://blog.wfilterngf.com/content/binary/Gargoyle ___005.jpg" border="0"></p>
<p></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.wfilterngf.com/?feed=rss2&#038;p=168</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WFilter deployment with a network tap.</title>
		<link>http://blog.wfilterngf.com/?p=170</link>
		<comments>http://blog.wfilterngf.com/?p=170#comments</comments>
		<pubDate>Wed, 27 Mar 2013 09:22:52 +0000</pubDate>
		<dc:creator><![CDATA[WFilter]]></dc:creator>
				<category><![CDATA[Deployment]]></category>
		<category><![CDATA[How to filter internet access]]></category>
		<category><![CDATA[How to monitor internet usage]]></category>
		<category><![CDATA[Internet Monitoring]]></category>

		<guid isPermaLink="false">http://blog.imfirewall.us/WFilter+Deployment+With+A+Network+Tap.aspx</guid>
		<description><![CDATA[1. What is network tap? Network tap is also a good way to monitor network traffic. Comparing to &#8220;port mirroring&#8221; switch, it has several advantages: Handy and flexible, requires no power supply. Once a network tap is in place, the network can be monitored without interfering with the network itself. Low cost, you even can [&#8230;]]]></description>
				<content:encoded><![CDATA[<h1>1. What is network tap?</h1>
<p><a href="http://en.wikipedia.org/wiki/Ethernet_tap" target="_blank">Network tap</a> is also a good way to monitor network traffic. Comparing to &#8220;port mirroring&#8221; switch, it has several advantages:</p>
<ol>
<li>Handy and flexible, requires no power supply.</li>
<li>Once a network tap is in place, the network can be monitored without interfering with the network itself.</li>
<li>Low cost, you even can dry it by yourself.</li>
</ol>
<p>Guide to make a network tap can be found at below links:</p>
<ol>
<li><a href="http://greatscottgadgets.com/throwingstar/" target="_blank">Throwing Star LAN Tap</a></li>
<li><a href="http://www.enigmacurry.com/category/diy/" target="_blank">Building an Ethernet Tap</a></li>
<li><a href="http://ossmann.blogspot.ca/2011/02/throwing-star-lan-tap.html" target="_blank">Throwing Star LAN Tap</a></li>
<li><a href="http://thnetos.wordpress.com/2008/02/22/create-a-passive-network-tap-for-your-home-network/" target="_blank">Create a passive network tap for your home network</a></li>
</ol>
<p>The disadvantages of network tap:</p>
<ol>
<li>Can not monitor gigabit networks. Requires &#8220;filterable tap&#8221;.</li>
<li>The monitoring port does not allow outgoing traffic. Therefore you need three network cards in the monitoring computer, two for monitoring, another for communication.</li>
</ol>
<p>This blog will guide you to deploy WFilter with &#8220;Throwing Star LAN Tap&#8221;.</p>
<h1>2. Deploy the LAN Tap.</h1>
<p>First, you need to attach three network cards in the monitoring computer. </p>
<p><img src="http://blog.wfilterngf.com/content/binary/NetWorkTap_01.jpg" border="0" height="83" width="625"></p>
<p>In this example, this lan tap is connected between the router and first switch(J1 and J2). Monitoring ports J3 and J4 are connected to two adapters of the monitoring computer.</p>
<p><img src="http://blog.wfilterngf.com/content/binary/NetWorkTap_00.jpg" border="0" height="400" width="587"></p>
<p>Actually it does not require ip address for the monitoring adapters. In this example, we assign &#8220;192.168.1.181&#8243;, &#8220;192.168.1.182&#8243; to the two monitoring adapters(Assigning an ip address makes it easier for us to identify the adapter in WFilter). The third adapter is assigned with &#8220;192.168.2.189&#8243;.</p>
<p><img src="http://blog.wfilterngf.com/content/binary/NetWorkTap_04.jpg" border="0"></p>
<h1>3. Setup WFilter</h1>
<p>Check the two monitoring adapters in &#8220;System Settings&#8221;-&gt;&#8221;Monitoring Settings&#8221;. The blocking adapter shall be choosed as the third adapter for sending blocking packets.</p>
<p><img src="http://blog.wfilterngf.com/content/binary/NetWorkTap_05.jpg" border="0"></p>
<p>Now we&#8217;re able to monitor client computers. You will notice that one monitoring adapter only get incoming packets, while another adapter only get outgoing packets. This is how network tap is designed.</p>
<p><img src="http://blog.wfilterngf.com/content/binary/NetWorkTap_06[1].jpg" border="0"><br />
<img src="http://blog.wfilterngf.com/content/binary/NetWorkTap_07.jpg" border="0"></p>
<p>Client computers also can be blocked.</p>
<p><img src="http://blog.wfilterngf.com/content/binary/NetWorkTap_12.jpg" border="0"></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.wfilterngf.com/?feed=rss2&#038;p=170</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Management of multiple deparments in WFilter</title>
		<link>http://blog.wfilterngf.com/?p=177</link>
		<comments>http://blog.wfilterngf.com/?p=177#comments</comments>
		<pubDate>Fri, 18 Jan 2013 06:06:46 +0000</pubDate>
		<dc:creator><![CDATA[WFilter]]></dc:creator>
				<category><![CDATA[How to monitor internet bandwidth]]></category>
		<category><![CDATA[How to monitor internet usage]]></category>

		<guid isPermaLink="false">http://blog.imfirewall.us/Management+Of+Multiple+Deparments+In+WFilter.aspx</guid>
		<description><![CDATA[You may use WFilter to setup internet access policies for network computers. However, it could be a very complicated mission for IT department to set the policies when you have a lot of departments and users. In this case, the solution is to setup multiple WFilter operators for departments. Each operator only can set policies [&#8230;]]]></description>
				<content:encoded><![CDATA[<p>You may use WFilter to setup internet access policies for network computers. However, it could be a very complicated mission for IT department to set the policies when you have a lot of departments and users.</p>
<p>In this case, the solution is to setup multiple WFilter operators for departments. Each operator only can set policies for users in certain departments. For example, department manager has the privilege to set internet policies for department staffs.</p>
<p>In this topic, I will guide you to manage multiple operators in WFiler Enteprise 4.0.</p>
<h1>1. Add departments</h1>
<p>You can add departments in <b>Policy Settings</b>-><b>Department Settings</b></p>
<p><img src="http://blog.wfilterngf.com/content/binary/muti_depart01.JPG" border="0"></p>
<h1>2. Add operators</h1>
<p>Add operators in <b>System Settings</b>-><b>Manage Operators</b>.</p>
<p><img src="http://blog.wfilterngf.com/content/binary/muti_depart02.JPG" border="0"></p>
<p>The &#8220;Supervising Dept.&#8221; defines the users whom this operator can see and configure. You also can define the WFilter menu for each operator. </p>
<p><img src="http://blog.wfilterngf.com/content/binary/muti_depart03.JPG" border="0"></p>
<h1>3. Policy Settings</h1>
<p>You can define departments&#8217; ip ranges in &#8220;Default Ip Policy&#8221;. So ip addresses will be added to certain deparment automatically.</p>
<p><img src="http://blog.wfilterngf.com/content/binary/muti_depart04.JPG" border="0"></p>
<h1>4. Operator Features</h1>
<p>In &#8220;User-computer table&#8221;, operator can only see users in its &#8220;Supervising Dept.&#8221;.</p>
<p><img src="http://blog.wfilterngf.com/content/binary/muti_depart05.JPG" border="0"></p>
<p>You can schedule standard reports to be sent to the department managers.</p>
<p><img src="http://blog.wfilterngf.com/content/binary/muti_depart06.JPG" border="0"></p>
<p><img src="http://blog.wfilterngf.com/content/binary/muti_depart07.JPG" border="0"></p>
<p></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.wfilterngf.com/?feed=rss2&#038;p=177</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to identify computers in WFilter?</title>
		<link>http://blog.wfilterngf.com/?p=201</link>
		<comments>http://blog.wfilterngf.com/?p=201#comments</comments>
		<pubDate>Wed, 26 Jan 2011 02:39:11 +0000</pubDate>
		<dc:creator><![CDATA[WFilter]]></dc:creator>
				<category><![CDATA[Content Filter]]></category>
		<category><![CDATA[How to block internet]]></category>
		<category><![CDATA[How to monitor internet usage]]></category>

		<guid isPermaLink="false">http://blog.imfirewall.us/How+To+Identify+Computers+In+WFilter.aspx</guid>
		<description><![CDATA[WFilter can monitor and filter computers internet activities in your network. In WFilter, two monitoring modes are available: &#8220;by ip address&#8221; and &#8220;by MAC address&#8221;. In &#8220;by ip address&#8221; monitoring mode, WFilter identifies a computer based on its ip address, while it identifies a computer based on its MAC address in &#8220;by mac address&#8221; monitoring [&#8230;]]]></description>
				<content:encoded><![CDATA[<p>WFilter can monitor and filter computers internet activities in your network. In WFilter, two monitoring modes are available: &#8220;by ip address&#8221; and &#8220;by MAC address&#8221;. In &#8220;by ip address&#8221; monitoring mode, WFilter identifies a computer based on its ip address, while it identifies a computer based on its MAC address in &#8220;by mac address&#8221; monitoring mode.</p>
<p>However, if computers ip addresses are not fixed in your network. You might have trouble to identify a computer to set its monitoring/blocking policy. </p>
<p>This tutorial will introduce you several solutions to identify computers in your network in WFilter.</p>
<h1>1. Monitor and block by AD users</h1>
<p>Since WFilter can be integrated with Microsoft active directory, you don&#8217;t need to face the trouble of identifying computers if you have an available AD.</p>
<p>With &#8220;account monitoring&#8221; enabled, you can set blocking policy based on AD users, despite which computers they are using. </p>
<p>Please check this document for more details about &#8220;account monitoring&#8221;: <a href="http://www.wfiltericf.com/help/doc/WFilter_Account.htm">How to do monitoring based on user accounts?</a></p>
<h1>2. Identify computers by MAC addresses</h1>
<p>With &#8220;by mac address&#8221; monitoring mode, WFilter identifies a computer by its MAC address. MAC address is assigned by the manufacturer of a network interface card (NIC) and are stored in its hardware. It won&#8217;t change unless the NIC hardware is replaced.</p>
<p>When you set a recording policy or blocking policy to one computer in &#8220;user-computer table&#8221;, certain settings will be bound to its mac address. Even its ip address is changed, certain settings will not be lost.</p>
<p>However, &#8220;By MAC address&#8221; monitoring mode is only available for single-segment networks, because a computer&#8217;s mac address can not be retrieved when it&#8217;s located behind a router.</p>
<p>Therefore, in a single-segment network, &#8220;by mac addresses&#8221; will be a good choice if your ip addresses are dynamic. </p>
<h1>3. Identify computers by IP addresses</h1>
<p>If your network is multi-segments, you only can use &#8220;by ip address&#8221; monitoring mode. Therefore, we recommend you to make ip addresses static in a multi-segments network. If you want to leave the ip addresses as dynamic, the only solution left is &#8220;Monitor and block by AD users&#8221; as discussed above.</p>
<p>More information, please check <a href="http://www.wfiltericf.com/WFilter.htm">&#8220;WFilter Enterprise&#8221;.</a></p>
<p>Other related links:</p>
<p><a href="How+To+Block+Internet+Downloading.aspx">How to block internet<br />
downloading?</a><br /><a href="How+To+Monitor+Internet+Usage+On+Company+Network.aspx">How to monitor<br />
internet usage on company networks?</a><br /><a href="Internet+Monitoring+Software+For+Business.aspx">Internet monitoring<br />
software for business</a><br /><a href="How+To+Filter+Web+Surfing.aspx">How to<br />
filter web surfing?</a><br /><a href="How+To+Block+Websites+And+Restrict+Internet+Access.aspx">How to block<br />
websites and restrict internet access?</a><br /><a href="How+To+Block+HTTPS+Websites+On+My+Network.aspx">How to block HTTPS<br />
websites on my network?</a><a class="TitleLinkStyle" href="How+To+Setup+Ipmac+Binding+In+WFilter.aspx" rel="bookmark"></a><br />
<a class="TitleLinkStyle" href="How+To+Setup+Ipmac+Binding+In+WFilter.aspx" rel="bookmark">How to setup ip-mac binding in WFilter?</a><br /><a class="TitleLinkStyle" href="How+To+Block+Facebook+At+Work+Of+Network+Computers.aspx" rel="bookmark">How to block facebook at work of network computers?</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.wfilterngf.com/?feed=rss2&#038;p=201</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How WFilter works to block internet connections in network?</title>
		<link>http://blog.wfilterngf.com/?p=205</link>
		<comments>http://blog.wfilterngf.com/?p=205#comments</comments>
		<pubDate>Fri, 10 Dec 2010 06:14:37 +0000</pubDate>
		<dc:creator><![CDATA[WFilter]]></dc:creator>
				<category><![CDATA[How to filter internet access]]></category>
		<category><![CDATA[How to monitor internet usage]]></category>

		<guid isPermaLink="false">http://blog.imfirewall.us/How+WFilter+Works+To+Block+Internet+Connections+In+Network.aspx</guid>
		<description><![CDATA[How WFilter works to monitor and archive internet activities? WFilter is an enterprise Internet filtering software program. A business or organization can implement its Internet communication policy into WFilter and let it perform the work. WFilter intercepts, records and monitors Internet behaviors of users on a network, for the purpose of ensuring policy compliance, or [&#8230;]]]></description>
				<content:encoded><![CDATA[<h1>How WFilter works to monitor and archive internet activities?</h1>
<p>WFilter is an enterprise Internet filtering software program. A business or<br />
organization can implement its Internet communication policy into<br />
WFilter and let it perform the work.<br />
  	WFilter intercepts, records and monitors Internet behaviors of users<br />
on a network, for the purpose of ensuring policy compliance, or<br />
measurement on job performance in an organization.</p>
<p>A mirroring port replicates the data from other ports or VLAN&#8217;s. To monitor all internet activity, WFilter needs to be connected to a mirroring port of your switch.&nbsp; And the mirroring port shall be configured to mirror your internet traffic. </p>
<p>When connected to a mirroring port, WFilter gets packet copies of all internet traffic, then decodes and saves them into log files. This is how WFilter works to monitor internet usage. </p>
<p>For more information about how to setup port mirroring, please check: <a href="http://www.wfiltericf.com/help/doc/deployment_example.htm">WFilter Deployment Examples.</a><br />To check whether your port mirroring is properly configured, please check: <a href="http://blog.wfilterngf.com/How+To+Check+Whether+Port+Mirroring+Settings+Are+Correct.aspx">How to check whether port mirroring is properly configured?</a><br />If you don&#8217;t have a manageable switch, you need to setup a windows gateway or proxy server to do monitoring, please check: <a href="http://blog.wfilterngf.com/Why+A+Port+Mirroring+Switch+Is+Required+To+Monitor+My+Network+How+To+Monitor+Internet+Usage+Without+A+Manageable+Switch.aspx">How to monitor internet usage without a manageable switch?</a></p>
<h1>How WFilter works to block internet connections?</h1>
<p>Many users had asked: &#8220;Since WFilter only handles packet copies and the original packets don&#8217;t pass through WFilter machine, how WFilter works to block internet connections?&#8221; </p>
<p>Actually, there are two filtering technology: pass-through filtering and pass-by filtering. </p>
<p>With a pass-through filtering solution, packets shall pass through the filtering product; if a packet needs to be blocked, the filtering product just drop it.</p>
<p>However, a pass-by filtering product only handles copies of network packets, it can not hold the original packets. Therefore, it sends RST packets to terminate TCP connections. This is how WFilter works to block connections.</p>
<p>Please notice: </p>
<p>1. Since WFilter needs to send RST packets to block a connection, the &#8220;blocking adapter&#8221; of WFilter shall be able to access your network. The blocking adapter shall be configured in &#8220;System Settings&#8221;-&gt;&#8221;Monitoring Settings&#8221; of WFilter.</p>
<p>2. Some switches do not allow outgoing traffic on the mirroring port, if so, you need to setup a separate NIC as the blocking adapter. Even outgoing traffic is allowed on the mirroring port, we recommend you to use a secondary NIC for blocking when you&#8217;re managing over 100 computers.&nbsp; Otherwise, the monitoring adapter will be overloaded.</p>
<p>3. If you have multiple VLANs, the blocking adapter shall belong to a VLAN which can communicate with other VLANs.</p>
<p>4. Sometimes you might need to set &#8220;Automatic Metric&#8221; of the <span class="searchword">blocking</span> <span class="searchword">adapter</span> for windows to recognize this adapter as the primary adapter. Please check this blog topic: <a class="TitleLinkStyle" rel="bookmark" href="Blocking+Adapter+Doesnt+Work+When+Using+Two+Network+Cards+With+WFilter.aspx"><span class="searchword">Blocking</span> <span class="searchword">adapter</span> doesn&#8217;t work when using two network cards with WFilter.</a></p>
<p>For more information about difference of the two filtering solutions, please check: <a class="TitleLinkStyle" rel="bookmark" href="Whats+The+Difference+Between+Passby+Filtering+And+Passthrough+Filtering.aspx">What&#8217;s the difference between Pass-by <span class="searchword">filtering</span> and Pass-through <span class="searchword">filtering</span>?</a><br />More details about WFilter filtering technology, please check: <a href="http://www.wfiltericf.com/WFilter_Technologies_and_Security_Introduction.htm">WFilter Technologies and Security</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.wfilterngf.com/?feed=rss2&#038;p=205</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
