Hi again, I am part of a corporate network with more than 2000 computers. I saw in my cisco router computers scanning others random networks on port 135/tcp [it sounds blaster/sasser/..]so, this core router is exporting flows [netflow v5] to my netflow server[flow-tools/flowscan/JKFlow]. The question is:
How can I configure dscan in order to know which computers are scanning the network? Is there another way to report something like this using any of the packets of flow-tools? regards... Israel Garcia Alvarez Linux Counter User #196178 Corporacion CIMEX Villa Clara _______________________________________________ Flow-tools mailing list [EMAIL PROTECTED] http://mailman.splintered.net/mailman/listinfo/flow-tools
