Solved

net traffic analyzer for linux firewall needed - looking for software suggestions

Posted on 2002-04-29
8
273 Views
Last Modified: 2013-11-16
net traffic analyzer for linux firewall needed - looking for software suggestions

Here is what I'm looking for:
A tiny console tool which dynamically shows all incoming nettraffic.

Here is what I want to improve:
A linux firewall (SuSE 7.3) with tools like (tail -f /var/log/firewall and iptraf [from Gerard Paul Java])

Any software suggestions ?
What experience did you make ? and with wich software ?

Thanks for your help

mathias



0
Comment
Question by:mfuerlinger
  • 2
  • 2
  • 2
  • +2
8 Comments
 
LVL 51

Expert Comment

by:ahoffmann
ID: 6978353
0
 
LVL 79

Expert Comment

by:lrmoore
ID: 6980363
try the man pages for tcpdump. If you don't have it, it is freely available.
0
 
LVL 40

Expert Comment

by:jlevie
ID: 6980455
I find that ntop (http://www.ntop.org) is a very nice traffic analyzer for networks in general. You can monitor overall traffic as well as see statistics relating to a single host, like who they are talking to and how much data is assocaited with a connection.
0
Complete VMware vSphere® ESX(i) & Hyper-V Backup

Capture your entire system, including the host, with patented disk imaging integrated with VMware VADP / Microsoft VSS and RCT. RTOs is as low as 15 seconds with Acronis Active Restore™. You can enjoy unlimited P2V/V2V migrations from any source (even from a different hypervisor)

 
LVL 1

Author Comment

by:mfuerlinger
ID: 6982101
hi Irmoore
, tried 'tcpdump' before but got stuck somewhere in the manual.
trying again...more precise:
searching a way to report all unknown incomming nettraffic except port 80 on the firewals eth0 dynamically on stdout.
Did not find a really helpfull expression and/or switch in 'tcpdump' yet.
...


salut ahoffmann
just downloaded mrtg2.9.18pre9 - hold on.
...
0
 
LVL 79

Expert Comment

by:lrmoore
ID: 6982131
Try Ethereal as an alternative. It might be easier to set filters.
http://www.ethereal.com/download.html

What do you have in front of the firewall for a router? If it is a Cisco router, you can setup access-lists to send all that traffic off to a syslog server..
0
 
LVL 51

Expert Comment

by:ahoffmann
ID: 6982203
hmm, seems that you need to clarify what you want to see:
   a) just packet headers
   b) packet content
   c) data streams (packets belonging/related to a connection)
   d) statistics about traffic (that's what I assumed according to the question)

for a) and b) go with tcpdump, or ethereal if you know how to use a mouse
for c) ethereal might be the better choice, there are some more of such programs
0
 
LVL 1

Accepted Solution

by:
smisk earned 100 total points
ID: 7057379
Try this for tcpdump :

tcpdump -x -X -i eth0 'dst 192.168.0.10 and dst port not 80 and src net not 192.168.0.0/24'

Where the following applies :

192.168.0.10 : firewall that you want to monitor.
80 : http port.
192.168.0.0/24 : subnet on which to allow incoming traffic from w/out printing to stdout.  use this if you have some trusted hosts on a network (you said all "unkown incoming traffic").

Also, if you're doing this over an ssh connection you probably want to add 'and host not my.ip.address' so your ssh connection doesn't flood the screen.

tcpdump has a lot of really great features.  Check the man pages for more useful options (ie, 'tcp' if you only want to see tcp traffic).

Steve
0
 
LVL 1

Author Comment

by:mfuerlinger
ID: 8101791
Finally to finish this question.
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
copying evtx files while system is running 2 58
SQL won't work after disabling SSL3 / TLS1 3 47
Admin account lockout 10 39
exchange, email gateway 2 29
This article outlines the process to identify and resolve account lockout in an Active Directory environment.
Each year, investment in cloud platforms grows more than 20% (https://www.immun.io/hubfs/Immunio_2016/Content/Marketing/Cloud-Security-Report-2016.pdf?submissionGuid=a8d80a00-6fee-4b85-81db-a4e28f681762) as an increasing number of companies begin to…
Email security requires an ever evolving service that stays up to date with counter-evolving threats. The Email Laundry perform Research and Development to ensure their email security service evolves faster than cyber criminals. We apply our Threat…
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …

770 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question