Forums

Skip to content

Advanced search
  • Quick links
    • Unanswered topics
    • Active topics
    • Search
  • FAQ
  • Login
  • Register
  • Board index Assistance Networking & Security
  • Search

Firewall analyzer?

Having problems getting connected to the internet or running a server? Wondering about securing your box? Ask here.
Post Reply
Advanced search
5 posts • Page 1 of 1
Author
Message
kmj0377
Guru
Guru
User avatar
Posts: 397
Joined: Fri Sep 26, 2003 6:53 am

Firewall analyzer?

  • Quote

Post by kmj0377 » Thu Jul 20, 2006 9:40 pm

Is there any good utility to analyze traffic going through a firewall and present it in a meaningful way? I've looked and I must be searching for the wrong stuff because I can't find any. It'd be nice to have a graph of some kind describing the traffic and be able to look at summaries for traffic by IP.
Top
azuriel
Apprentice
Apprentice
User avatar
Posts: 166
Joined: Sun Feb 27, 2005 9:14 pm
Contact:
Contact azuriel
Website

  • Quote

Post by azuriel » Thu Jul 20, 2006 9:51 pm

I don't know much about "nice graphical" ways of measuring firewall traffic, but I can point you towards a couple utilities:

-Wireshark (Ethereal): Packet sniffer, lets you record all the packets going by on the network and analyze the traffic a bit. It can do some pretty good sorts and searches, but it's not that graphical. You can definitely look at traffic by IP, though, but recording packets like that fills up disk space fast.
-Snort: IDS, probably overkill for what you want, and it has a graph generator called snortplot. I haven't used snortplot myself, but I'm guessing it works. It's not as easy as install & run, but it's not difficult either.
-You can also look around for some log parsers, they might be able to meet your requirements.

Hoped these helped a bit. What kind of firewall do you have, and what is the purpose of these statistics?
Adopt an unanswered post
TJGames.org

The folly of mistaking a torrent of verbiage for a spring of capital truths, and oneself for an oracle, is inborn in us. -Valery
Top
lkarayan
n00b
n00b
Posts: 14
Joined: Mon Mar 28, 2005 7:57 pm

ntop?

  • Quote

Post by lkarayan » Thu Jul 20, 2006 11:57 pm

ntop will tell you the bandwith you are using, and the sites that are being connected to. But it won't tell you what the firewall rejected.
Top
kmj0377
Guru
Guru
User avatar
Posts: 397
Joined: Fri Sep 26, 2003 6:53 am

  • Quote

Post by kmj0377 » Fri Jul 21, 2006 1:53 am

azuriel wrote:I don't know much about "nice graphical" ways of measuring firewall traffic, but I can point you towards a couple utilities:

-Wireshark (Ethereal): Packet sniffer, lets you record all the packets going by on the network and analyze the traffic a bit. It can do some pretty good sorts and searches, but it's not that graphical. You can definitely look at traffic by IP, though, but recording packets like that fills up disk space fast.
-Snort: IDS, probably overkill for what you want, and it has a graph generator called snortplot. I haven't used snortplot myself, but I'm guessing it works. It's not as easy as install & run, but it's not difficult either.
-You can also look around for some log parsers, they might be able to meet your requirements.

Hoped these helped a bit. What kind of firewall do you have, and what is the purpose of these statistics?
We mostly want to see who has been connecting the most and to what and we'd also like to see what kind of bandwith usage we're using (looks like ntop might do that). We're using Shorewall to configure iptables mostly for forwarding to our servers and VPN purposes.
Top
azuriel
Apprentice
Apprentice
User avatar
Posts: 166
Joined: Sun Feb 27, 2005 9:14 pm
Contact:
Contact azuriel
Website

  • Quote

Post by azuriel » Fri Jul 21, 2006 5:02 am

A quick google search for "iptables graph" turned up this article, Making Graphs with PostgreSQL & R. It's basically dumping the syslog entries that iptables generates into a database with some parsing tricks, and then using that to generate graphs. If you've got some experience working in higher level scripting languages and with databases, you can probably figure out how to do this using the article as a starting point. It shouldn't be too hard to adapt it to say, PHP or Python and MySQL.

I'm pretty sure you could do this with snort if you wanted, but it's almost certainty extra overhead assuming that you can do it with just iptables. The general idea would be making snort detect up and log all packets and dump it in snort's nice and fast binary log format, then using barnyard to put the log into a database, and THEN hopefully snortplot does what you want.
Adopt an unanswered post
TJGames.org

The folly of mistaking a torrent of verbiage for a spring of capital truths, and oneself for an oracle, is inborn in us. -Valery
Top
Post Reply

5 posts • Page 1 of 1

Return to “Networking & Security”

Jump to
  • Assistance
  • ↳   News & Announcements
  • ↳   Frequently Asked Questions
  • ↳   Installing Gentoo
  • ↳   Multimedia
  • ↳   Desktop Environments
  • ↳   Networking & Security
  • ↳   Kernel & Hardware
  • ↳   Portage & Programming
  • ↳   Gamers & Players
  • ↳   Other Things Gentoo
  • ↳   Unsupported Software
  • Discussion & Documentation
  • ↳   Documentation, Tips & Tricks
  • ↳   Gentoo Chat
  • ↳   Gentoo Forums Feedback
  • ↳   Duplicate Threads
  • International Gentoo Users
  • ↳   中文 (Chinese)
  • ↳   Dutch
  • ↳   Finnish
  • ↳   French
  • ↳   Deutsches Forum (German)
  • ↳   Diskussionsforum
  • ↳   Deutsche Dokumentation
  • ↳   Greek
  • ↳   Forum italiano (Italian)
  • ↳   Forum di discussione italiano
  • ↳   Risorse italiane (documentazione e tools)
  • ↳   Polskie forum (Polish)
  • ↳   Instalacja i sprzęt
  • ↳   Polish OTW
  • ↳   Portuguese
  • ↳   Documentação, Ferramentas e Dicas
  • ↳   Russian
  • ↳   Scandinavian
  • ↳   Spanish
  • ↳   Other Languages
  • Architectures & Platforms
  • ↳   Gentoo on ARM
  • ↳   Gentoo on PPC
  • ↳   Gentoo on Sparc
  • ↳   Gentoo on Alternative Architectures
  • ↳   Gentoo on AMD64
  • ↳   Gentoo for Mac OS X (Portage for Mac OS X)
  • Board index
  • All times are UTC
  • Delete cookies

© 2001–2026 Gentoo Foundation, Inc.

Powered by phpBB® Forum Software © phpBB Limited

Privacy Policy

 

 

magic