![Fortinet FortiWAN Handbook Download Page 254](http://html1.mh-extra.com/html/fortinet/fortiwan/fortiwan_handbook_2322088254.webp)
Statistics
Traffic Statistics for Tunnel Routing and IPSec
IPSec traffic. The way to identify the traffic that is transferred through Tunnel Routing or IPSec is to create a BM class
and BM filter to classify the traffic by the source IP and destination IP that are defined in Tunnel Routing's routing rules
or IPSec's Quick Mode selectors.
Page
Statistics > Tunnel Traffic
(See "
") is the only page reports the traffic statistics
about Tunnel Routing. Although traffic statistics is reported by the defined Tunnel Routing groups, statistics of the
individual application in the tunnel traffic is unavailable here.
Page
Statistics > IPSec
(See "
") tells nothing about traffic statistics of IPSec, only IPSec
connectivity states are reported here.
FortiWAN Reports
Different from BM logs, service of traffic that is transferred through Tunnel Routing is indicated as GRE in Reports
(See "
Reports > Bandwidth Usage > Services
"). Individual service type of the original packets encapsulated by
Tunnel Routing becomes invisible in Reports. The GRE traffic passing through FortiWAN from other VPN devices and
the GRE traffic generated by FortiWAN Tunnel Routing will be counted into service GRE in page Reports > Bandwidth
Usage > Services, which might be confusing. Drilling it down by Internal IP, Inclass or Outclass could figure it out. As
for traffic transferred through IPSec, Reports counts the traffic by individual application (the original packets
before/after be ESP encapsulated/decapsulated) rather than counting it into service ESP. FortiWAN IPSec is
transparent to Reports statistics.
Here are a summary of discussion above.
Traffic transferred through IPSec Tunnel mode
Original traffic
ESP encapsulated
traffic
BM Control
O
X
BM log
O
X
Reports
O
X
Traffic transferred through Tunnel Routing or IPSec Transport mode
Original traffic
GRE encapsulated
traffic
ESP encapsulated
traffic
BM Control
O
X
X
BM log
O
X
X
Reports
X
O
X
We have a simple example to explain the difference between the statistics ways. Consider that user A generates
60MB FTP traffic and 80MB HTTP traffic and transfer them through normal IP routing, user B generates 40MB FTP
traffic and 20MB HTTP traffic and transfer them through Tunnel Routing (through one tunnel group). All the traffic is
controlled by Bandwidth Management, thus there will be four BM logs indicating:
254
FortiWAN Handbook
Fortinet Technologies Inc.