Version 1.0 looks great so far. I am currently monitoring our firewall to check what protocols are being used from the internal network out to the internet. However, the probe is also reporting traffic generated from my internal 10.x.x.x nodes to other nodes on the internal network. How can I use the filter so that it will not report this internal traffic?
Bjorn J. Kvande
Re: how to filter out internal network
Sep 19, 2003 8:58 AM
At the moment, this can not be done by the filter. As long as any of the source/destination addresses goes through the filter (as it will if an internal host talks to an external host) it will be counter.
We might need to rethink the filter so you can filter out pairs of addresses (filter out all conversations 10.0.0.0 to 10.255.255.255).