Identifying Traffic
I recently set-up a dedicated server at an isp.
Immediately, the isp began billing me for 20gb of traffic a day.
The only services availible for the outside are ssh and tomcat.
The tomcat logs are almost empty.
Netstat -an reveals no suspicous connections or activity.
IP Accounting with iptables reveals minimal activity on the filter table.
There seems to be some significant activity on the mangle table prerouting chain.
There are no mangle rules specified.
What might this indicate? How can I dig further?
Thanks for any help...
|