MetricSplit › Guides › Check bandwidth usage on a WAN link
How to check bandwidth usage on a WAN link
To check how much of a WAN link is used, you need four things: the link's capacity in each direction, its traffic in each direction over time, the busiest periods in business hours, and what the traffic is. Here are the ways to get each, from a one-off check on the router to continuous monitoring.
1. Know the capacity, per direction
Start with the speed you pay for, from the contract or the provider's portal. Many links are asymmetric: a 100 Mbps download link may have a much smaller upload. Write both down. A percentage is only meaningful against the right capacity, and the interface's own speed (often 1,000 Mbps on the port) is usually not the circuit's speed.
2. A quick check on the router
Most routers show a recent rate per interface. On Cisco IOS and IOS XE, for example, show interfaces reports an input and output rate averaged over the last few minutes (the averaging period is set by load-interval, as short as 30 seconds). Other vendors have an equivalent page or command.
This is good for answering "is it busy right now?". It doesn't tell you how busy the link was yesterday afternoon, or what the traffic was.
3. Counters over time
Polling the interface byte counters every few minutes (usually over SNMP) and graphing the difference gives you traffic over time, in each direction. This shows the daily pattern and the busy hours.
Two things to watch: the polling interval (a 5-minute reading already smooths out short bursts; an hourly or daily average hides almost everything, see how bandwidth is measured), and which interface you poll (it must be the one facing the WAN circuit).
4. Flow records to see what the traffic is
Counters tell you how much; flow records (NetFlow v9 or IPFIX) also tell you what: which applications, which hosts, which direction, through which interface. Enable a flow export on the router or SD-WAN controller and send it to a collector. See the setup guides for each vendor.
5. Read it at the busiest business-hours moments
The number that matters for a capacity decision is how full the link runs when people are working and the link is busiest, in each direction. A good figure is the 95th percentile of 5-minute readings in business hours over at least a week: it ignores the few busiest minutes and the quiet nights, and shows what users actually feel.
| At its busiest business-hours moments | What it usually means |
|---|---|
| Over 85% | Users feel it. Act now: move traffic, limit what doesn't need the room, or upgrade. |
| 60 to 85% | Busy but working. Plan before it crosses 85%. |
| Under 60% | Room to spare. |
| Under 1% | Either the link is far bigger than the site needs, or the export doesn't cover its WAN interface. |
6. Check both directions and every link at the site
Look at download and upload separately: one can be full while the other is idle. If the site has two links, check both: one may be full while the other has room, which is a reason to rebalance rather than upgrade.
How MetricSplit does this for every link
MetricSplit receives your routers' flow records and measures every WAN link this way: 5-minute readings per direction, judged on the 95th percentile of business hours over 7 days, with the traffic classified as business, neutral or non-business. Each link gets a decision: rebalance, right-size, restrict or upgrade.