|
楼主 |
发表于 2002-11-25 16:33:53
|
显示全部楼层
比如。你的 Linux 做网关,人家在聊QQ。
你用 netstat -M 可以看到吗?不可以,那是针对 2.2.x 核心的。
用 iptstate 可以很清楚地看到 多少个连接,一个人同时上了几个 QQ 都可以看到。
比如: 我现在上了两个QQ:
127.0.0.1,40811 127.0.0.1,22 tcp TIME_WAIT 0:01:52
127.0.0.1,40786 127.0.0.1,825 tcp TIME_WAIT 0:00:40
127.0.0.1,40803 127.0.0.1,825 tcp TIME_WAIT 0:01:16
192.168.20.1,40799 192.168.20.1,143 tcp TIME_WAIT 0:00:57
192.168.20.2,137 192.168.20.255,137 udp 0:00:21
192.168.20.2,37100 192.168.20.1,993 tcp CLOSE 0:00:02
192.168.20.19,2883 66.218.77.70,80 tcp SYN_SENT 0:00:47
192.168.20.19,1898 207.46.106.125,1863 tcp ESTABLISHED 119:58:14
192.168.20.19,4000 218.17.209.19,8000 udp 0:02:28
192.168.20.19,1051 205.188.10.27,5190 tcp ESTABLISHED 111:00:28
192.168.20.19,2901 211.78.213.163,80 tcp TIME_WAIT 0:01:48
192.168.20.19,2890 66.218.77.70,80 tcp SYN_SENT 0:01:11
192.168.20.19,2902 211.78.213.163,80 tcp TIME_WAIT 0:01:52
192.168.20.19,2903 211.78.213.163,80 tcp TIME_WAIT 0:01:51
192.168.20.19,2905 211.78.213.163,80 tcp TIME_WAIT 0:01:52
192.168.20.19,2906 211.78.213.163,80 tcp CLOSE 0:00:07
192.168.20.19,2907 211.78.213.163,80 tcp FIN_WAIT 0:01:56
192.168.20.19,2896 66.218.77.70,80 tcp SYN_SENT 0:01:35
192.168.20.19,2908 211.78.213.163,80 tcp SYN_SENT 0:01:57
192.168.20.19,2909 211.78.213.163,80 tcp ESTABLISHED 119:59:59
192.168.20.19,2904 66.218.77.70,80 tcp SYN_SENT 0:01:59
192.168.20.19,2736 192.168.20.1,993 tcp ESTABLISHED 119:48:46
192.168.20.19,4236 65.54.195.253,80 tcp ESTABLISHED 76:18:50
192.168.20.19,4001 202.104.129.253,8000 udp 0:02:41
192.168.20.19,4366 216.136.225.84,5050 tcp ESTABLISHED 119:53:19
有人说,我 sniffer 不就可以吗 ? 可是那不直观。 |
|