Hi, On Fri, Jul 08, 2011 at 03:58:54PM +0000, Jeff Cartier wrote: > I'm just curious as to how 'you' would go about tracking down a > user that *may* possibly be downloading large amounts of data > causing congestion on a link. For instance, I had a case this > morning with an internal IP address of 10.x.x.x that showed a 900MB > conversation over TCP 80 (HTTP) to an ip address of 174.120.5.220.
ntop on a sniffer port is nice.
gert
--
USENET is *not* the non-clickable part of WWW!
//www.muc.de/~gert/
Gert Doering - Munich, Germany [email protected]
fax: +49-89-35655025 [email protected]
pgp9SDoo2ismN.pgp
Description: PGP signature
_______________________________________________ cisco-nsp mailing list [email protected] https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/
