AW: flow -> web
tom
tier1 at ncinet.de
Mon Feb 6 08:43:46 UTC 2006
If one does not wanna use netflow, but ipaccounting, then this is a also a
nice solution...
http://ipacco.sourceforge.net/index.php
tom from munich/germany
-----Ursprüngliche Nachricht-----
Von: owner-nanog at merit.edu [mailto:owner-nanog at merit.edu] Im Auftrag von
Randy Bush
Gesendet: Montag, 6. Februar 2006 09:25
An: nanog at nanog.org
Betreff: Re: flow -> web
folk have asked me to summarize. so here it goes
"Justin M. Streiner" <streiner at cluebyfour.org> and Nicolas Strina
<nicolas.strina at noc.ip-man.net> recommended the nfdump nfsen pair,
http://nfsen.sourceforge.net
http://nfdump.sourceforge.net
Chris Kuethe <chris.kuethe at gmail.com> and Peter Wohlers <pedro at whack.org>
recommended ntop
http://www.ntop.org/
Peter Wohlers <pedro at whack.org> also recommended Stager
http://software.uninett.no/stager/?page=docs
Steven Rakick <stevenrakick at yahoo.com> recommended nSight
http://www.obtuse.net/software/nsight
Tony Hacche <hacche at gmail.com> recommended Crannog's NetFlow Tracker
http://www.crannog-software.com/index.php?go=Product.ShowDetail&ProductID=1
Jared Mauch <jared at puck.nether.net> has a tool to detect and highlight ddos
symptoms, but it does not have per-protocol sexy graphs. looks very useful
for ddos detection, though
---
i am currently playing with nfsdump/nfsen
randy
More information about the NANOG
mailing list