[84752] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: Tools classifying network traffic to applications

daemon@ATHENA.MIT.EDU (Petri Helenius)
Thu Sep 22 11:36:10 2005

Date: Thu, 22 Sep 2005 18:35:46 +0300
From: Petri Helenius <pete@he.iki.fi>
To: "Christopher L. Morrow" <christopher.morrow@mci.com>
Cc: NANGO <nanog@merit.edu>
In-Reply-To: <Pine.GSO.4.58.0509221501110.26672@parapet.argfrp.us.uu.net>
Errors-To: owner-nanog@merit.edu


Christopher L. Morrow wrote:

>>which can't really tell bittorrent (or ssh or aim or...) over tcp/80 from
>>http over tcp/80... I think Joe's looking for something that knows what
>>protocols look like below the port number and can spit out numbers for
>>that... these, it would seem to me, would all require in-line traffic
>>capture or mirrored port (mirrored traffic, not necessarily an ethernet
>>port mirror) to be effective.
>>
>>    
>>
We can do that up to 2Gbps; http://www.rommon.com/  , BitTorrent, KaZaa, 
eDonkey, HTTP, etc. supported.

Pete


home help back first fref pref prev next nref lref last post