Nick_Parker Posted March 3, 2010 Posted March 3, 2010 Hello On our ISA Server I have NetMeter running so I can see when the internet usage spikes. I noticed today that the outgoing traffic has been sitting at 60kb/s constantly since this morning. It's a very unnatural usage, even when all our labs are in use the outgoing traffic never reaches these sort of levels, and especially doesn't sit at this level for hours. Is there any quick way of seeing where this traffic is coming from? I imagine I can look at the ISA logs, but you can only generate the report 24 hours later. I suspect somebody has limewire/frostwire open somewhere...
FN-GM Posted March 3, 2010 Posted March 3, 2010 I suspect somebody has limewire/frostwire open somewhere... Do you not block P2P ports?
Nick_Parker Posted March 3, 2010 Author Posted March 3, 2010 Not at the moment, its a new ISA Setup (Threat Management Gateway actually) and I have the rule set to "Allow all Outbound Traffic" while I finish setting everything up, stupid I know. What ports would you recommend I block?
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now