Yah - I see this as something really beyond what I'd expect ntop to do. IDS/netmanagement/other kinds of tools maybe, but not ntop.
On 3/22/06, Burton Strauss <[EMAIL PROTECTED]> wrote: > And that would depend - at least partly - on whether the spec is open or > closed. And whether each packet is tagged or just the first. And on how > much resources you wanted to spend per-packet to figure it out. > > Remember: ntop sees packets - we don't do full-up connection tracking like > some OSes and firewalls do. > > -----Burton _______________________________________________ Ntop mailing list [email protected] http://listgateway.unipi.it/mailman/listinfo/ntop
