You can set up flow monitoring. NTOP would be a good open source choice.
It will give you monthly/daily/hourly/etc reports of all the traffic coming through it. You can see what protocols, what destinations and what source ip addresses are involved.
NTOP consists of two parts. There’s a collector and a sensor. The collector has to be on the gateway. If you’re using a cisco device, they come with nflow, open source and other sensors are usually going to be sflow. NTOP can collect both. Here’s an nflow/sflow sensor if you don’t like ntops that works on SUSe. For different types of sensors just google (sflow|net-flow).
Hope this helps.