1 Jun 06:30
Re: Direction of src and dest
Robert Leyba <r_leyba14 <at> yahoo.com>
2007-06-01 04:30:49 GMT
2007-06-01 04:30:49 GMT
Hi Carter,
I've recreated the scenario. I'm sending you what might be useful. Note that
I FTP'd the file from 10.22.97.107 to 10.52.32.215
root <at> cpocts:/tmp# racount -r outfile - src host 10.52.32.215 and dst host
10.22.97.107
racount records total_pkts src_pkts dst_pkts
total_bytes src_bytes dst_bytes
sum 3 174 66 108
157624 4050 153574
root <at> cpocts:/tmp# racount -r outfile - dst host 10.52.32.215 and src host
10.22.97.107
racount records total_pkts src_pkts dst_pkts
total_bytes src_bytes dst_bytes
sum 5 36 21 15
2735 1360 1375
root <at> cpocts:/tmp# ra -r outfile - src host 10.52.32.215 and dst host
10.22.97.107 -L0
StartTime Flgs Proto SrcAddr Sport Dir
DstAddr Dport SrcPkts DstPkts SrcBytes DstBytes State
14:09:40.619797 e tcp 10.52.32.215.ftp-da ->
10.22.97.107.igi-lm 4 3 328 182 FIN
14:09:58.597238 e d tcp 10.52.32.215.ftp-da ->
10.22.97.107.dbsa-l 62 105 3722 153392 FIN
root <at> cpocts:/tmp# ra -r outfile - dst host 10.52.32.215 and src host
10.22.97.107 -L0
StartTime Flgs Proto SrcAddr Sport Dir
(Continue reading)
RSS Feed