From owner-freebsd-questions@FreeBSD.ORG Wed Apr 30 12:17:26 2003 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id D52E437B401 for ; Wed, 30 Apr 2003 12:17:26 -0700 (PDT) Received: from blacklamb.mykitchentable.net (170-215-84-217.br1.elk.ca.frontiernet.net [170.215.84.217]) by mx1.FreeBSD.org (Postfix) with ESMTP id 32FCE43FBD for ; Wed, 30 Apr 2003 12:17:26 -0700 (PDT) (envelope-from drew@mykitchentable.net) Received: from tagalong (unknown [165.107.42.110]) by blacklamb.mykitchentable.net (Postfix) with SMTP id AD40FEE52A; Wed, 30 Apr 2003 12:17:25 -0700 (PDT) Message-ID: <011b01c30f4d$223b0ea0$6e2a6ba5@tagalong> From: "Drew Tomlinson" To: , References: <000001c30f31$c6bc01d0$0701a8c0@darryl> Date: Wed, 30 Apr 2003 12:17:25 -0700 MIME-Version: 1.0 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: 7bit X-Priority: 3 X-MSMail-Priority: Normal X-Mailer: Microsoft Outlook Express 6.00.2800.1158 X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165 Subject: Re: Firewall & Security Question X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 30 Apr 2003 19:17:27 -0000 ----- Original Message ----- From: "Darryl Hoar" To: Sent: Wednesday, April 30, 2003 9:01 AM Subject: Firewall & Security Question > Greetings, > my firewall is running 4.4-stable. I have ipfilter > configured and running. I have ipnat running. > All the PC's on my line access our DSL line > through the firewall. > > I have tripwire configured and running on my firewall. > > Due to some recent activity, I need to be able to > monitor who is doing what on the internet. IE, > maybe a DOS attack being launched through our > connection, etc. More than likely, I have a user > with Kazaa or some other service that is periodically > pumping out quite a bit of data. > > What should I use to snoop this out? Should I > connect something between the firewall and the > ADSL router to log whats happening ? > > Any ideas greatly appreciated. This periodic activity > brought our DSL throughput down to the point I was > receiving calls. I've found ntop to be useful in diagnosing my network. I see it as kind of like a web interface to tcpdump captures. Anyway it's in the ports and was easy to setup. HTH, Drew