From owner-freebsd-security@FreeBSD.ORG Wed Mar 3 06:55:32 2004 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 95FF516A4D1 for ; Wed, 3 Mar 2004 06:55:32 -0800 (PST) Received: from otter3.centtech.com (moat3.centtech.com [207.200.51.50]) by mx1.FreeBSD.org (Postfix) with ESMTP id 3A63E43D2D for ; Wed, 3 Mar 2004 06:55:32 -0800 (PST) (envelope-from anderson@centtech.com) Received: from centtech.com (neutrino.centtech.com [10.177.171.220]) by otter3.centtech.com (8.12.3/8.12.3) with ESMTP id i23EtVE8055323; Wed, 3 Mar 2004 08:55:31 -0600 (CST) (envelope-from anderson@centtech.com) Message-ID: <4045F1BC.5040006@centtech.com> Date: Wed, 03 Mar 2004 08:54:52 -0600 From: Eric Anderson User-Agent: Mozilla/5.0 (X11; U; FreeBSD i386; en-US; rv:1.6) Gecko/20040205 X-Accept-Language: en-us, en MIME-Version: 1.0 To: Francisco Reyes References: <20040303094647.J93367@zoraida.natserv.net> In-Reply-To: <20040303094647.J93367@zoraida.natserv.net> Content-Type: text/plain; charset=us-ascii; format=flowed Content-Transfer-Encoding: 7bit cc: FreeBSD Security List Subject: Re: How to monitoring activity on a card? X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Security issues [members-only posting] List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 03 Mar 2004 14:55:32 -0000 Francisco Reyes wrote: > My setup 4.9 stable with IPFW. Machine acts as gateway for two machines. > > What are my options on monitoring activity on my external card? > > This morning I noticed my DSL modem activity light is blinking non-stop. > Looking at /var/log/ don't see anything suspicious. > > I feel tempted to add "log" to all my ipfw pass rules, but wonder if there > isn't a better way. > > I am mostly concerned there is either some kind of attack going on or > somehow the machine was hacked and it's running something it's not > supposed to. I like trafshow for watching it "live". Eric -- ------------------------------------------------------------------ Eric Anderson Sr. Systems Administrator Centaur Technology Today is the tomorrow you worried about yesterday. ------------------------------------------------------------------