В одной из тем меня надоумили поставить NetFlow - систему контроля за трафиком.
Дистрибутив - Debian Squeeze
Пользовался указаниями в статье http://xgu.ru/wiki/NetFlow
1.Ставлю сенсор
$ sudo aptitude --prompt --without-recommends install softflowd
INTERFACE="eth0"
OPTIONS="-n 127.0.0.1:9995"
bkois@bkois-linux:~$ sudo service softflowd start
bkois@bkois-linux:~$ sudo softflowctl statistics
softflowd[3046]: Accumulated statistics:
Number of active flows: 49
Packets processed: 691
Fragments: 0
Ignored packets: 60 (60 non-IP, 0 too short)
Flows expired: 0 (0 forced)
Flows exported: 0 in 0 packets (0 failures)
Packets received by libpcap: 751
Packets dropped by libpcap: 0
Packets dropped by interface: 0
-w /var/flow/fgupmzrta 0/127.0.0.1/9995
$ sudo mkdir /var/flow
$ sudo mkdir /var/flow/fgupmzrta
$ sudo service flow-capture restart
ft-v05.2012-07-19.122101+0400 ft-v05.2012-07-19.124501+0400
ft-v05.2012-07-19.123001+0400 tmp-v05.2012-07-19.124701+0400