>  http://iptraf.seul.org
>  http://www.cacti.net
I neglected to mention three things:
1) iptraf is great for real-time data, much like Wireshark running in
2) Cacti is great for trending/historical data, and because it can
aggregate all your switch ports into one view. (You get to play "Spot the
Big Peaks on the Graph".)
3) ntop pulls it all together VERY nicely into an "almost real-time"
report of who's talking to whom, AND what type of traffic they are
transferring. (Or, at least, "what type of traffic they APPEAR to be
transferring".) This one would also be best run from a machine attached to
the monitor port (or on the firewall, if that's possible).
Sam Hooker [log in to unmask] |
Consulting Engineer, Partner |
ClearBearing Group (802)846-1855 |
Internet engineering | network services |