So, would a monitoring tool still show anything if this traffic is being blocked at their modem/router?
Only on any ports that where traffic is being allowed through the router.
I looked at tcpdump/ipaudit and it's either too humid or they seem too tough to implement, given the fact he is gonna switch ISP regardless.
HenWen gives you a GUI monitoring tool which lists the top 10 attacks the machine is receiving. But it may be too much hassle in this case. Good for dedicated servers though.
So far opinions have lead me to believe it's not 'them' causing this but some other possibly malicious entity, if so does anyone think that this kind of attack could occur despite who the ISP is? In other words do any ISPs attempt to stop or filter this kind of thing or are we on our own?
Sadly it's a fact of life on the internet in this day and age. How many difficulties you have is somewhat the luck of the draw, to the rest of the net it all just looks like another IP address. It's possible the traffic may be originating inside BigPond, which might mean a change of ISPs would reduce it. But don't count on it!
Have fun, Shay -- =========================== Shay Telfer ================================ Perth, Western Australia Technomancer Chronopolis Quiz Day Opinions for hire [POQ] Sun. March 14, Hyde Park Hotel [EMAIL PROTECTED] fnord <http://chronopolis.sf.org.au/>

