On Wed, Apr 02, 2003 at 12:20:36PM -0600, Paul Crittenden wrote:
> I have an unusual, I think, question. I maintain a firewall here for
> Simpson College. I am getting complaints from folks about someone
> inside my firewall who is scanning ports on other networks. I log
> unsuccessful connections on my firewall but not successful ones.
> 
> So my question is how can I figure out who is doing the port scanning
> from the inside to the outside?

I'm not aware of anything in iptables that would allow you to monitor
traffic in this manner.  However, ntop or ngrep may be of use for this.  

> Also, is this list archived somewhere? I can't find it in my
> subscription confirmation email.

The list is archived in two locations:

   http://asgardsrealm.net/lurker/splash/index.html
   http://www.mail-archive.com/firewall%40asgardsrealm.net/
   
-- 
Jamin W. Collins

Reply via email to