Hi there,

I'm noticing a lot of dynamic nat bindings at my internet router ( 4000
out of a maximum of 8000).  This router services a small school with
about 20 users.  The school uses its own router that is natting.  The
majority of the nat bindings belong to that school's nat router.  So I
don't have any visibility past their router.

On the host info page of their router, Ntop is showing that the domain
port 53 usage is 2754/130.2 Kbytes and http port 80 is at 1492/2.0
Mbytes.  I guessing the first number represents the number of open
sessions ?  Why so many ??? With only 20 users (not simultaneous I'm
sure) ??

I have had host warnings before (yellow flag) showing that there were a
lot of host contacts ( over 1200).   I just can't believe so many dns
sessions are required and why they stay open so long.  Is this an
indication of P2P traffic or worm/virus infestation(s) ??

Using ntop version : 3.3.5

thanks,
Guy

_______________________________________________
Ntop mailing list
[email protected]
http://listgateway.unipi.it/mailman/listinfo/ntop

Reply via email to