Re: Bandwidth consume by IP address

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: Peter N. M. Hansteen
Date: Saturday, October 2, 2010 - 12:35 am

Hermes Ojeda Ruiz <hermes.o.r@gmail.com> writes:


There are a few options available. One is to write the rule set with
labels to collect statistics, making sure the labels are one per IP
address.  The other main option is to use pflow(4), with 'set
state-defaults pflow' or 'keep state (pflow)' for individual rules in
your rule set, set up a collector somewhere and extract the data you
need per IP address.  If you go for pflow, the pflow man page will get
you started.  I'd recommend taking a look at Michael W. Lucas' recent
book for the Netflow analysis part, while the upcoming second edition
of the Book of PF contains a bit of material about both approaches too
(the first edition has only the labels part).

- Peter
-- 
Peter N. M. Hansteen, member of the first RFC 1149 implementation team
http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/
"Remember to set the evil bit on all malicious network traffic"
delilah spamd[29949]: 85.152.224.147: disconnected after 42673 seconds.
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Bandwidth consume by IP address, Hermes Ojeda Ruiz, (Fri Oct 1, 6:57 pm)
Re: Bandwidth consume by IP address, Bret S. Lambert, (Fri Oct 1, 9:59 pm)
Re: Bandwidth consumed by computer on the network, Hermes Ojeda Ruiz, (Fri Oct 1, 11:42 pm)
Re: Bandwidth consume by IP address, Peter N. M. Hansteen, (Sat Oct 2, 12:35 am)
Re: Bandwidth consume by IP address, Stuart Henderson, (Sat Oct 2, 6:28 am)