9/21 I was asked to be doing some basic system admin stuff when
our company's Sys Admin is not avaliable. First thing I want to
do is to monitor the local area network, as there are certain
time of day when i know someone is abusing the network so much
that he/she alone sucked 99% of the bandwidth. Any lead on
how to appropach this? and what is a typical tool being used
to monitor packet?
\_ mrtg, smoke ping, router configs
\_ Snort, ethereal (works on Windows.) Set up a SPAN or mirror
port on a switch (assuming you have a switched network) and
start working back towards individual ports. Use mrtg to
collect statistics on individual ports. -John
\_ Thanks. I'll get start on it. -kngharv
\_ That's not basic stuff. Has anyone asked you to find this person
and destroy their career? If not then let it go. If you go on,
then use some common sense before outing them. If it's kiddie
pr0n, sure go ahead. If they're just dicking around on ebay or
something equally harmless, give them a chance to stop. Don't
just be the storm trooper gestapo for some management prick. It
isn't your duty to ruin lives on command as a sysadmin.
\_ I second this. I bet this person is just downloading mp3's.
If you just plan to figure out who it is and ask them to stop,
that is one thing, but don't kick it upstairs. Before you
even start doing system administration, you should get a copy
of Nemeth and read "The Politics of System Administration,"
which is the last chapter.
\_ just downloading mp3s? who wants the RIAA suing your
company? |