From mboxrd@z Thu Jan 1 00:00:00 1970 From: "Chris Sellers" Date: Tue, 01 May 2001 03:28:14 +0000 Subject: [LARTC] interface information MIME-Version: 1 Content-Type: multipart/mixed; boundary="----=_NextPart_000_002E_01C0D1B4.15462190" Message-Id: List-Id: To: lartc@vger.kernel.org This is a multi-part message in MIME format. ------=_NextPart_000_002E_01C0D1B4.15462190 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable I want to know if it is possible to setup an ipchians rule to looks for = an IP moving large amounts of data on an interface. For Example: One of my servers connected to an interface is being attacked. I want to = check the interface and get the IP that doing the dirty deed.=20 Is this possible to do with ipchains and how would I go about = implementing it? Thanks ------=_NextPart_000_002E_01C0D1B4.15462190 Content-Type: text/html; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable
I want to know if it is possible to = setup an=20 ipchians rule to looks for an IP moving large amounts of data on an=20 interface.
 
For Example:
One of my servers connected to an = interface is=20 being attacked. I want to check the interface and get the IP that doing = the=20 dirty deed.
 
 
Is this possible to do with ipchains = and how would=20 I go about implementing it?
 
Thanks
 
------=_NextPart_000_002E_01C0D1B4.15462190-- _______________________________________________ LARTC mailing list / LARTC@mailman.ds9a.nl http://mailman.ds9a.nl/mailman/listinfo/lartc HOWTO: http://ds9a.nl/2.4Routing/