From owner-freebsd-questions@FreeBSD.ORG Wed Apr 30 09:13:25 2003 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 2788237B401 for ; Wed, 30 Apr 2003 09:13:25 -0700 (PDT) Received: from diana.northnetworks.ca (att-ws20.switchview.com [216.13.70.20]) by mx1.FreeBSD.org (Postfix) with ESMTP id 2E7DE43F85 for ; Wed, 30 Apr 2003 09:13:24 -0700 (PDT) (envelope-from iaccounts@northnetworks.ca) Received: from diana.northnetworks.ca (localhost.northnetworks.ca [127.0.0.1]) h3UGDMDI043204; Wed, 30 Apr 2003 12:13:22 -0400 (EDT) (envelope-from iaccounts@northnetworks.ca) Received: from localhost (iaccounts@localhost)h3UGDMZo043201; Wed, 30 Apr 2003 12:13:22 -0400 (EDT) X-Authentication-Warning: diana.northnetworks.ca: iaccounts owned process doing -bs Date: Wed, 30 Apr 2003 12:13:21 -0400 (EDT) From: Steve Bertrand To: Darryl Hoar In-Reply-To: <000001c30f31$c6bc01d0$0701a8c0@darryl> Message-ID: <20030430121228.H58756-100000@diana.northnetworks.ca> MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII cc: freebsd-questions@freebsd.org Subject: Re: Firewall & Security Question X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 30 Apr 2003 16:13:25 -0000 > Due to some recent activity, I need to be able to > monitor who is doing what on the internet. IE, > maybe a DOS attack being launched through our > connection, etc. More than likely, I have a user > with Kazaa or some other service that is periodically > pumping out quite a bit of data. > > What should I use to snoop this out? Should I > connect something between the firewall and the > ADSL router to log whats happening ? man tcpdump(8) Also, possibly install ethereal. Steve > > Any ideas greatly appreciated. This periodic activity > brought our DSL throughput down to the point I was > receiving calls. > > thanks, > Darryl > _______________________________________________ > freebsd-questions@freebsd.org mailing list > http://lists.freebsd.org/mailman/listinfo/freebsd-questions > To unsubscribe, send any mail to "freebsd-questions-unsubscribe@freebsd.org" >