im having some trouble with ntop-3.2-1.2.fc4.rf.
I monitor my server which have permanently 2 icecast source stream connected on it.
iI don't have any FTP server on that machine.
After some times it seems that Icecast (tcp:8000) traffic stats goes to FTP traffic graphs.
I have tried to run " tcpdump -v -i any tcp or udp port 20 or 21" and i dont see any traffic on this ports.
Here you can see the traffic of data hopping from Icecast to FTP graph:
http://img123.imageshack.us/my.php?image=capturentopicecast9dx.png
If someone have any idea about how to fixing it:)
Here is my protocol.list:
more /etc/ntop/protocol.list
FTP=ftp|ftp-data
HTTP=http|www|https|3128 3128 is Squid, the HTTP cache
DNS=name|domain
Telnet=telnet|login
NBios-IP=netbios-ns|netbios-dgm|netbios-ssn
Mail=pop-2|pop-3|pop3|kpop|smtp|imap|imap2
DHCP-BOOTP=67-68
SNMP=snmp|snmp-trap
NNTP=nntp
NFS=mount|pcnfs|bwnfs|nfsd|nfsd-status
X11=6000-6010
SSH=22|9022
#Peer-to-Peer Protocols
# ----------------------
Gnutella=6346|6347|6348
Kazaa=1214
WinMX=6699|7730
DirectConnect=0 Dummy port as this is a pure P2P protocol
eDonkey=4661-4665
#Instant Messenger
#-----------------
Messenger=1863|5000|5001|5190-5193
#Ports Ajoutés par nico
IceCast=8000
Quake3=27960
SSH=8022
_______________________________________________ Ntop mailing list [email protected] http://listgateway.unipi.it/mailman/listinfo/ntop
