Intrusion Detection Systems mailing list archives

dumping traffic on IPX


From: FMartins () pt imshealth com (Lisbon)
Date: Fri, 22 Oct 1999 17:59:52 +0200



Hi2all

I got a pratical question regarding logging excess of broadcasts in an internal network. If caused by someone on 
purpose, can be an IDS issue i suppose ... 
In a TCP/IP plus IPX enviroment i have excess of broadcasts because i cant have only IP on the network (yet...).
I want to log this using tcpdump, filtering in a way that only the traffic about this broadcasts appear, to made a easy 
readable report.
The question is with tcpdump the best way to log and then report it.
Thanks in advance for your help.

Kind Regards,
Fernando Martins



Current thread: