Hi,

On Fri, Jul 08, 2011 at 03:58:54PM +0000, Jeff Cartier wrote:
> I'm just curious as to how 'you' would go about tracking down a
> user that *may* possibly be downloading large amounts of data
> causing congestion on a link.  For instance, I had a case this
> morning with an internal IP address of 10.x.x.x that showed a 900MB
> conversation over TCP 80 (HTTP) to an ip address of 174.120.5.220.

ntop on a sniffer port is nice.

gert
-- 
USENET is *not* the non-clickable part of WWW!
                                                           //www.muc.de/~gert/
Gert Doering - Munich, Germany                             [email protected]
fax: +49-89-35655025                        [email protected]

Attachment: pgp9SDoo2ismN.pgp
Description: PGP signature

_______________________________________________
cisco-nsp mailing list  [email protected]
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/

Reply via email to