|
View:
New views
2 Messages
—
Rating Filter:
Alert me
|
|
|
|
|
|
Re: Does anyone on the list have experience with firewall log analyzers to monitor firewall...
by Tim E
::
Rate this Message:
Reply (Restricted by the Administrator) | Reply to Author | View Threaded | Show Only this Message I think what you're looking to do here will require a few programs.
1) A logging analyzer (for the completed connections) There are a few free ones, I would suggest giving them a shot. I personally haven't used any of them. 2) A traffic snmp monitor Personally I use Cacti for this, however there are many various snmp monitors. This will only give you a general view of traffic on each interface, not on a per policy hit. 3) Perhaps a real time session analyzer (during attacks, high traffic, etc.) I wrote a program called NSSA (Netscreen Session Analyzer) This basically reports on a live session table that you download by hand and gives you such information as connections/ports/source/dest/ etc.. This is public and free. On the other side, it would be a lot easier to use a Network General Sniffer type application. These do everything you request (short of policy denies/allows on the firewall) at a network level. This is a general overview of the options I think are viable. If you have any questions or want to talk about them in depth feel free to ask :) Tim Eberhard On 4/19/07, Jacob, Raymond A Jr <raymond.jacob@...> wrote: Subject: Does anyone on the list have experience with firewall log _______________________________________________ nn mailing list nn@... http://qorbit.net/mailman/listinfo/nn |
| Free Forum Powered by Nabble | Forum Help |