Path: csiph.com!x330-a1.tempe.blueboxinc.net!usenet.pasdenom.info!weretis.net!feeder4.news.weretis.net!news.glorb.com!border3.nntp.dca.giganews.com!border1.nntp.dca.giganews.com!nntp.giganews.com!npeer02.iad.highwinds-media.com!news.highwinds-media.com!feed-me.highwinds-media.com!spln!extra.newsguy.com!newsp.newsguy.com!news6 From: Harry Putnam Newsgroups: comp.os.linux.networking Subject: Re: DMZ for logging Date: Mon, 30 Jan 2012 09:40:15 -0500 Organization: Still searching... Lines: 16 Message-ID: <87bopls180.fsf@newsguy.com> References: <87mx95st8m.fsf@newsguy.com> NNTP-Posting-Host: p9fe40f05f5ba8cc41f4e5a6450c380b76e44d0912c09643a.newsdawg.com Mime-Version: 1.0 Content-Type: text/plain User-Agent: Gnus/5.110018 (No Gnus v0.18) Emacs/24.0.92 (gnu/linux) Cancel-Lock: sha1:t/ZJP0B/jVQlNrmEtmwzvZKl7QA= Xref: x330-a1.tempe.blueboxinc.net comp.os.linux.networking:1025 J G Miller writes: > On Sunday, January 29th, 2012, at 23:35:05h -0500, Harry Putnam explained: > >> I'd like to get a real good idea of what is coming at me from the >> internet. > > Maybe you should be looking at ntop to do this? > > How will ntop know about stuff that is blocked at the firewall that ntop sits behind. Or do you mean ntop on a DMZ machine. If so that is the topic here... how to setup a DMZ machine that just logs and then drops incoming.