how can I track who was using my bandwidth last night??

LadyDi

Member
Nov 6, 2000
57
0
0
Hey all,

I am in a quandry. I use MRTG to monitor bandwidth usage. Last night there was a large spike of traffic that I am able to map through the network. What I don't know how to do is to find out who or how that happened.

Recommend things I can use in the future to do this but right now I of course only have the tools that are already in use. Where should I start to find out what did this.

Attacker shows no scans, no one was in the building, we know it couldn't have been a customer because it didn't use the right interface for that, and it seems to have originated at a router but NOT at either of the subnets off that router.

Thanks,
Diana
 

spidey07

No Lifer
Aug 4, 2000
65,469
5
76
Is this LAN or WAN bandwidth? When you say "originated from the router" do you mean the router sourced the traffic?

No way to tell since it happened in the past. You need a very sophisticated hardware/software combination that logs all traffice. A LAN or WAN rmon probe would help.

 

LadyDi

Member
Nov 6, 2000
57
0
0
Thanks

I found 2 static ip routes going through the router in question. Internet traffic was looping through the network.

Di