From: Mike Brown (brownm1970~AT~hotmail.com)
Date: Thu Oct 07 2004 - 04:19:58 CEST
The analog (fwanalog) output appears to show "source" port statistics but not destination ports. I guess I'm not sure why I would care what the source port of an attacker is. Aren't I interested in the destination port? That is, the port they are hitting me on. Or is this just a semantics issue?
I'm running on Linux iptables 2.4.
I guess I would just expect to see a nice pie chart of attacked ports like they have on SANS: http://isc.sans.org/
This archive was generated by hypermail 2.1.5 : Thu Feb 24 2005 - 15:22:04 CET