From: Zakai Kinan (titanyen2000~AT~yahoo.com)
Date: Mon Feb 28 2005 - 03:48:25 CET
It was already at 0.5% and I dropped it to lower number. Am i supposed to get the type/name of attack on the graph? You have that on your example graph.
> * Zakai Kinan <titanyen2000~AT~yahoo.com> [2005-02-24
> > In the packet source host report, what is the
> other category so big? On
> > my report, it constitutes 95% blocking. what is
> the threshold under
> > which it will not show an IP/host?
> it is configurable in fwanalog.analog.conf.local:
> HOSTFLOOR 0.5%r # Hosts with at least
> 0.5 % of the blocked packets
> Just write a smaller number, e.g. 0.05%r and you
> will see more hosts with
> less packets.
This archive was generated by hypermail 2.1.5 : Tue Mar 01 2005 - 22:22:04 CET