Firewall Wizards mailing list archives

RE: Statistics for Firewalls


From: Joe Matusiewicz <joem () nist gov>
Date: Wed, 11 Sep 2002 11:49:54 -0400

At 04:01 PM 9/10/02, Christopher Hicks wrote:

I've been looking at ntop ( http://www.ntop.org ) for protocol statistical
analysis.  It looks like it does everything I could ever imagine wanting
for that sort of thing.  Does anyone have any experience with it,
positive, negative or otherwise?

I think it's marvelous. The only problem I had with it was on one of my networks. The firewall there averages 70,000 simultaneous connections and ntop keeps a record of all the ip addresses that goes through the network. Keeping track of so many addresses bogged down the hash memory so much until ntop was unusable. :( I wound up using iptraf there.

But ntop works great everywhere else I put it.


-- Joe

_______________________________________________
firewall-wizards mailing list
firewall-wizards () honor icsalabs com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


Current thread: