[76561] in North American Network Operators' Group
Re: identifying application type of network traffic
daemon@ATHENA.MIT.EDU (Suresh Ramasubramanian)
Thu Dec 16 04:54:58 2004
Date: Thu, 16 Dec 2004 15:24:30 +0530
From: Suresh Ramasubramanian <ops.lists@gmail.com>
Reply-To: Suresh Ramasubramanian <ops.lists@gmail.com>
To: Joe Shen <joe_hznm@yahoo.com.sg>
Cc: NANGO <nanog@merit.edu>
In-Reply-To: <20041216094149.57633.qmail@web53604.mail.yahoo.com>
Errors-To: owner-nanog-outgoing@merit.edu
On Thu, 16 Dec 2004 17:41:49 +0800 (CST), Joe Shen
<joe_hznm@yahoo.com.sg> wrote:
>
> My situation is not to apply QoS policy to those
> application but to get statistics of applications.
>
> According to netflow records, the traffic across our
> egress interface has port number range from 11 to
> 65534 , there is record for port 0!
> So, what are those applications ?
>
Passive fingerprinting is about the only thing that's going to tell
you, without actually sniffing the traffic that you're seeing.
Could be anything at all.
--
Suresh Ramasubramanian (ops.lists@gmail.com)