Snort mailing list archives

Re: IP Traffic


From: Rick <black.hawk () email it>
Date: Thu, 02 Jan 2003 15:55:56 +0100

I've already tried ntop but it groups all IP protocol non tcp/udp based in one group called "Other Procotols". Do you know if Darkstat or ipstat are able to work at IP level (in my case IPSec IP/50)?

Thanks

Regards,

Riccardo

At 12.35 02/01/2003, you wrote:
On Thu, Jan 02, 2003 at 12:18:31PM +0100, Rick wrote:
> Hi all,
>
> i would like to account all IPSec and VoIP traffic of my network, this for
> generate some statistics for net % usage.
>
> Do you know if exists an application that works with Snort to do that?
>
> Thank you
>
> Regards,
>
> Rick

Snort could probibly do that, but it is not the tool of choice. Ntop[1]
and Darkstat[2] comes to mind. I have a page on my private website
that lists cool tools that uses libpcap.. Have a look at it @
http://proxy.11a.nu/fun_with_pcap.php

Best regards
 Michael Boman

PS
 Feel free to suggest more cool tools to use
DS

[1] http://www.ntop.org/
[2] http://members.optushome.com.au/emikulic/net/darkstat/

--
Michael Boman
Security Architect, SecureCiRT (A SBU of Z-Vance Pte Ltd)
http://www.securecirt.com



-------------------------------------------------------
This sf.net email is sponsored by:ThinkGeek
Welcome to geek heaven.
http://thinkgeek.com/sf
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: