Want to improve this question? Update the question so it's on-topic for Stack Overflow.
Closed 12 years ago.
这是一个非常开放式的问题。
如果您有兴趣记录所有流量并将其保存以供将来分析,TCPDump 是您的最佳选择。可以使用适当的标志为您处理文件轮换和时间戳。 http://www.tcpdump.org/
如果您正在寻找源/目标 IP 和端口日志记录,netflow更方便,因为管理所需的资源和磁盘空间更少。这可以通过 nProbe http://www.ntop.org/nProbe.html 或 nfcapd 来完成http://manpages.ubuntu.com/manpages/intrepid/man1/nfcapd .1.html
您始终可以从路由器/防火墙捕获IP/端口信息。这可能是最简单的。
This is a very open ended question.
If you are interested in recorded ALL traffic to saving it for future analysis, TCPDump is the way to go. File rotation and timestamps can be taken care of for you with the proper flags. http://www.tcpdump.org/
If you are looking for Source/Dest IP and port logging, netflow is more convenient as it takes less resources and disk space to manage. This can be accomplished through nProbe http://www.ntop.org/nProbe.html or nfcapd http://manpages.ubuntu.com/manpages/intrepid/man1/nfcapd.1.html
You can always capture IP/port information from your router/firewall. This is probably the easiest.
您可以使用 tcpdump 查看数据包,或者如果您需要使用 Wireshark 的 GUI。
You can view packets with tcpdump or if you need a GUI with Wireshark.
由于您还没有绑定你的真实邮箱,如果其他用户或者作者回复了您的评论,将不能在第一时间通知您!
暂无简介
文章 0 评论 0
接受
发布评论
评论(2)
这是一个非常开放式的问题。
如果您有兴趣记录所有流量并将其保存以供将来分析,TCPDump 是您的最佳选择。可以使用适当的标志为您处理文件轮换和时间戳。 http://www.tcpdump.org/
如果您正在寻找源/目标 IP 和端口日志记录,netflow更方便,因为管理所需的资源和磁盘空间更少。这可以通过 nProbe http://www.ntop.org/nProbe.html 或 nfcapd 来完成http://manpages.ubuntu.com/manpages/intrepid/man1/nfcapd .1.html
您始终可以从路由器/防火墙捕获IP/端口信息。这可能是最简单的。
This is a very open ended question.
If you are interested in recorded ALL traffic to saving it for future analysis, TCPDump is the way to go. File rotation and timestamps can be taken care of for you with the proper flags. http://www.tcpdump.org/
If you are looking for Source/Dest IP and port logging, netflow is more convenient as it takes less resources and disk space to manage. This can be accomplished through nProbe http://www.ntop.org/nProbe.html or nfcapd http://manpages.ubuntu.com/manpages/intrepid/man1/nfcapd.1.html
You can always capture IP/port information from your router/firewall. This is probably the easiest.
您可以使用 tcpdump 查看数据包,或者如果您需要使用 Wireshark 的 GUI。
You can view packets with tcpdump or if you need a GUI with Wireshark.