- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- Port monitoring software for hpux 11.11
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-31-2007 12:28 PM
12-31-2007 12:28 PM
Need a tool to monitor traffic coming through our ftp port(s). Does anyone know of a port monitoring software that will allow us to identify the source (ip address would be great) of network traffic coming through a specific port.
Thank you for your responses.
Norm
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-31-2007 01:07 PM
12-31-2007 01:07 PM
Re: Port monitoring software for hpux 11.11
You might be able to use a repetitive 'lsof' to collect your information into a file that could be analyzed.
http://hpux.cs.utah.edu/hppd/hpux/Sysadmin/lsof-4.78/
Regards!
...JRF...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-31-2007 02:33 PM
12-31-2007 02:33 PM
Re: Port monitoring software for hpux 11.11
Like your idea, regarding a repitive lsof what did you have in mind, cron or ? If I run lsof with no options we should be able to find the process trying to login to via ftp (port12).
Thanks again.
Norm
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-31-2007 03:52 PM
12-31-2007 03:52 PM
Solution> Like your idea, regarding a repitive lsof what did you have in mind, cron or ?
Frankly, I was thinking of launching a 'lsof' using its repeat mode ('-r
http://www.netadmintools.com/html/lsof.man.html
You might find this useful, too:
http://www.opensource.apple.com/darwinsource/10.3/lsof-12/lsof/00QUICKSTART
Regards!
...JRF...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-01-2008 08:18 AM
01-01-2008 08:18 AM
Re: Port monitoring software for hpux 11.11
1. connections: ftpd -l
2. ftp commands: ftpd -l -L
3. input/output files: ftpd -l -L -i -o
4. every packet: use nettl (built-in) or wireshark (download)
The ftpd options are listed in the ftpd man page and must be changed in /etc/inetd.conf. The default location for these log entries is syslog.log and the facility used for ftpd is local5. Alternatively, you can use the /etc/ftpd/ftpaccess file to control logging options. Note that for option 4, the logs will be massive in size for a lot of ftp traffic.
Bill Hassell, sysadmin
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-02-2008 11:07 AM
01-02-2008 11:07 AM
Re: Port monitoring software for hpux 11.11
The lsof -i option did the job. Put lsof into cron and was able to find the ip address of the server submitting the ftp requests.
Norm
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-02-2008 11:15 AM
01-02-2008 11:15 AM
Re: Port monitoring software for hpux 11.11
Thanks for the ftpd options. Looks like wireshark has numerous pre-reqs. Will look into downloading and installing wireshark, it maybe useful in the future.
Norm
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-02-2008 03:34 PM
01-02-2008 03:34 PM
Re: Port monitoring software for hpux 11.11
- Wireshark is available for Windows too, and it can read dumps created by tcpdump or HP-UX's native nettl tools.
Both tcpdump and wireshark are available in the free Internet Express software package from software.hp.com.
It might be more convenient to install Wireshark on your local workstation instead of the HP-UX server.
- There is no need to waste CPU power to a separate monitoring program: ftpd is invoked through inetd, and inetd can log the source hostname and IP address of all incoming connection attempts. The connection attempt is logged before the FTP login prompt is sent, so it will get failed FTP logins too.
Just start inetd with option "-l" (NOTE: lowercase L, not number 1)... or send a "kill -QUIT" to a running inetd to toggle the connection logging on. The log messages will be stored to syslog, and they should be of the form
ftp/tcp: Connection from remote_host (IP_address)
How to get network traffic dump using HP-UX native tools:
http://www.compute-aid.com/nettl.html
(just use wireshark to view the dump instead of netfmt)
Wireshark:
http://www.wireshark.org
MK