[ Machiavelli... @ 27.10.2010. 18:43 ] @
Imam problem, prijatelju ce da iskljuce server. Ima nenormalni output traffic. Vec je dobio upozorenje ovo je pred iskljucenje! Ovo je deo mail koji su mu poslali Direction OUT Internal 213.239.*.* Threshold Packets 30.000 packets/s Sum 12.494.000 packets/300s (41.646 packets/s), 15 flows/300s (0 flows/s), 0,515 GByte/300s (14 MBit/s) External 96.38.136.139, 12.481.000 packets/300s (41.603 packets/s), 2 flows/300s (0 flows/s), 0,500 GByte/300s (13 MBit/s) External 89.216.218.89, 2.000 packets/300s (6 packets/s), 2 flows/300s (0 flows/s), 0,003 GByte/300s (0 MBit/s) External 94.189.163.133, 2.000 packets/300s (6 packets/s), 2 flows/300s (0 flows/s), 0,003 GByte/300s (0 MBit/s) External 93.86.253.223, 1.000 packets/300s (3 packets/s), 1 flows/300s (0 flows/s), 0,001 GByte/300s (0 MBit/s) External 109.245.183.64, 1.000 packets/300s (3 packets/s), 1 flows/300s (0 flows/s), 0,001 GByte/300s (0 MBit/s) External 89.216.23.52, 1.000 packets/300s (3 packets/s), 1 flows/300s (0 flows/s), 0,001 GByte/300s (0 MBit/s) External 213.198.226.249, 1.000 packets/300s (3 packets/s), 1 flows/300s (0 flows/s), 0,000 GByte/300s (0 MBit/s) External 92.60.228.44, 1.000 packets/300s (3 packets/s), 1 flows/300s (0 flows/s), 0,001 GByte/300s (0 MBit/s) External 178.223.86.15, 1.000 packets/300s (3 packets/s), 1 flows/300s (0 flows/s), 0,001 GByte/300s (0 MBit/s) External 188.2.76.83, 1.000 packets/300s (3 packets/s), 1 flows/300s (0 flows/s), 0,001 GByte/300s (0 MBit/s) External 91.185.102.168, 1.000 packets/300s (3 packets/s), 1 flows/300s (0 flows/s), 0,001 GByte/300s (0 MBit/s) External 109.93.25.38, 1.000 packets/300s (3 packets/s), 1 flows/300s (0 flows/s), 0,000 GByte/300s (0 MBit/s) Kako da ustanovim ko pravi ovaj ludi traffic? Evo upravo mu zatvaram OUTPUT firewall polisu (stavicu na default DROP) otvoricu samo 22 i 10000( on koristi webadmina). Kako na debain da vidim ko pravo ovaj traffic? Koji deamon? |