Hi again, I am part  of a corporate network with more than 2000 computers. I saw
in my cisco router computers scanning others  random networks on port 135/tcp
[it sounds blaster/sasser/..]so, this core router is exporting flows [netflow
v5] to my netflow server[flow-tools/flowscan/JKFlow]. The question is:

How can I configure dscan in order to know which computers are scanning the
network?
Is there another way to report something like this using any of the packets of
flow-tools?

regards...

Israel Garcia Alvarez
Linux Counter User #196178
Corporacion CIMEX Villa Clara


_______________________________________________
Flow-tools mailing list
[EMAIL PROTECTED]
http://mailman.splintered.net/mailman/listinfo/flow-tools

Reply via email to