Re: How to Log OUTGOING Packets w/ IPCHAINS

From: David
Date: 12/31/02

From: David <>
Date: Tue, 31 Dec 2002 16:41:59 GMT

Ted Smith wrote:
> Hello. My ISP tells me that my server periodically gets attacked and
> pumps out about 30MB/sec of traffic.. I have bastille and pmfirewall
> running, but those are only logging blocked outgoing packets. How
> would I go about detecting the outgoing packets to figure out what is
> causing this problem? Thanks a lot!

Run "snort" or "tcpdump"

tcpdump -i eth0 -s 1500 -v -n -w /path/to/somefile
   # this will log output to "somefile"

