Jump to content

Recommended Posts

Posted

Hello :)

 

On our ISA Server I have NetMeter running so I can see when the internet usage spikes.

I noticed today that the outgoing traffic has been sitting at 60kb/s constantly since this morning.

It's a very unnatural usage, even when all our labs are in use the outgoing traffic never reaches these sort of levels, and especially doesn't sit at this level for hours.

Is there any quick way of seeing where this traffic is coming from?

 

I imagine I can look at the ISA logs, but you can only generate the report 24 hours later.

 

I suspect somebody has limewire/frostwire open somewhere...

Posted

Not at the moment, its a new ISA Setup (Threat Management Gateway actually)

and I have the rule set to "Allow all Outbound Traffic" while I finish setting everything up, stupid I know.

 

What ports would you recommend I block?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...