I want to know if it is possible to setup an
ipchians rule to looks for an IP moving large amounts of data on an
interface.
For Example:
One of my servers connected to an interface is
being attacked. I want to check the interface and get the IP that doing the
dirty deed.
Is this possible to do with ipchains and how would
I go about implementing it?
Thanks
|