Re: OT: Monitoring Conversations w/port numbers

From: Carlos G Mendioroz (tron@huapi.ba.ar)
Date: Mon Oct 21 2002 - 21:09:55 GMT-3


You may want to try netflow based tools.
Cisco has some, and there are some free ones out there
(e.g. CAIDA's cflowd) that are worth a try.
There are also some tools to summarize flow data.
And you may want to look at Dave Plonka's flowscan...

(Just filing some "flowdumps" will enable yoou to answer
questions like "which was the top talker yesterday between
1pm and 2pm, or how many bytes where sent originating at port 1214).

McClure, Allen wrote:
> Sorry for the off-topic, but I thought I'd run this by you guys.
>
> Does anyone have any good ideas for monitoring traffic types and
> quantity via WAN links (or anywhere else for that matter)?
>
> I'm tasked frequently with questions like "Determine how much bandwidth
> X application is using on the WAN". Obviously applications vary so much
> that it can be difficult. Cisco's RMON doesn't seem to do the trick and
> I'm trying to avoid using a sniffer. I usually come up with some
> creative method of accomplishing this, but with Netmeeting and other P2P
> stuff it can be a pain.
>
> Thanks in advance for any comments.
>
> Allen McClure
> MCSE, CCNP, CCDP
> YUM! Brands, Inc.
> Sr. Network Analyst
> NEW E-Mail - mailto:allen.mcclure@yum.com
> 972-338-7494
>
>
>
> This communication is confidential and may be legally privileged. If you are
> not the intended recipient, (i) please do not read or disclose to others, (ii)
> please notify the sender by reply mail, and (iii) please delete this
> communication from your system. Failure to follow this process may be
> unlawful. Thank you for your cooperation.
>

-- 
Carlos G Mendioroz  <tron@huapi.ba.ar>  LW7 EQI  Argentina


This archive was generated by hypermail 2.1.4 : Tue Nov 05 2002 - 08:35:53 GMT-3