Re: [Soekris] Network content monitoring on Net6501 - any, suggestions?

2012-09-26 Thread Robert Guerra
In regards to Snort running on the Net6501 on PfSense 2.1 (details below), I have been using it for a while. 2.1-BETA0 (i386) built on Thu Sep 20 13:34:11 EDT 2012 FreeBSD pfsense.pvt 8.3-RELEASE-p4 FreeBSD 8.3-RELEASE-p4 #1: Thu Sep 20 14:01:16 EDT 2012 root@snapshots-8_3-i386.builders.pfsen

Re: [Soekris] Network content monitoring on Net6501 - any, suggestions?

2012-09-26 Thread Giles Coochey
On 26/09/2012 14:51, Josh Hoppes wrote: Snort can capture anything you tell it too, just need to configure the right rules to capture what you're looking for. I'm not an expert but they should be plenty of resources available. True, and if you want to go further you can write your own rules. T

Re: [Soekris] Network content monitoring on Net6501 - any, suggestions?

2012-09-26 Thread Josh Hoppes
Snort can capture anything you tell it too, just need to configure the right rules to capture what you're looking for. I'm not an expert but they should be plenty of resources available. On Wed, Sep 26, 2012 at 7:47 AM, Robin Kipp wrote: > Hi Josh, > >> If you're up for the task, snort could do t

Re: [Soekris] Network content monitoring on Net6501 - any, suggestions?

2012-09-26 Thread Robin Kipp
Hi Chris, first off, thanks a lot for your reply! > If you want to store and analyse the actual content, snort might meet your > needs. Argus is also capable of capturing a portion of each packet for > later analysis. Thanks a lot for that! I'll have a closer look at Snort and also check out A

Re: [Soekris] Network content monitoring on Net6501 - any, suggestions?

2012-09-26 Thread Robin Kipp
Hi Josh, > If you're up for the task, snort could do the trick. I already have Snort running on the box, but that only detects and alerts for abnormal network activities (well, I'll still have to do some fine tuning). So, if you've got any advice / resources on how to do the things I've describ

Re: [Soekris] Network content monitoring on Net6501 - any, suggestions?

2012-09-25 Thread Chris Wilson
Hi Robin, On Tue, 25 Sep 2012, Robin Kipp wrote: >>> Network content monitoring on Net6501 - any >>> suggestions? >> ntop > > Thanks, but I don't really think this is what I want... Ntop appears to > be a tool that just shows network usage, e.G. bandwidth used by certain > types of traffic,

Re: [Soekris] Network content monitoring on Net6501 - any, suggestions?

2012-09-25 Thread Frank Schuhmann
kris] Network content monitoring on Net6501 - any, suggestions? Hello Robin, There are several solutions or better methods out there. What is about Nagios? Did you played with the idea to have a quick look over or dedicated view on? <http://www.nagios.org/> Or you use TCPDUMP and sto

Re: [Soekris] Network content monitoring on Net6501 - any, suggestions?

2012-09-25 Thread Josh Hoppes
If you're up for the task, snort could do the trick. On Tue, Sep 25, 2012 at 3:25 PM, Robin Kipp wrote: > Hi Bill, > >>> Network content monitoring on Net6501 - any >>> suggestions? >> ntop > > Thanks, but I don't really think this is what I want... Ntop appears to be a > tool that just sho

Re: [Soekris] Network content monitoring on Net6501 - any, suggestions?

2012-09-25 Thread Robin Kipp
Hi Bill, >> Network content monitoring on Net6501 - any >> suggestions? > ntop Thanks, but I don't really think this is what I want... Ntop appears to be a tool that just shows network usage, e.G. bandwidth used by certain types of traffic, etc... This isn't what I want, I'm looking for so

Re: [Soekris] Network content monitoring on Net6501 - any, suggestions?

2012-09-25 Thread Bill Michaelson
On 09/23/2012 08:00 AM, soekris-tech-requ...@lists.soekris.com wrote: Network content monitoring on Net6501 - any suggestions? ntop ___ Soekris-tech mailing list Soekris-tech@lists.soekris.com http://lists.soekris.com/mailman/listinfo/soekris-t

[Soekris] Network content monitoring on Net6501 - any suggestions?

2012-09-22 Thread Robin Kipp
Hello all, I am using a Soekris Net6501 running Debian Squeeze as a router (Eth0 is connected to the internet, other ports are used to connect network clients). Now, I'm looking for a software that can run on the Net6501 and will capture certain kinds of network traffic, such as instant messages,