nTOP on Untangle 6.2

I’ve had several people email me regarding information on configuring nTop on Untangle version 6.x (0,1,2).

nTop is a network traffic probe that shows the network usage, similar to what the popular “top” Linux command does. ntop is based on libpcap and it has been written in a portable way in order to virtually run on every Unix platform and on Win32 as well.

nTop users can use a a web browser (e.g. Firefox) to browse through ntop (that acts as a web server) traffic information and get a dump of the network status. In the latter case, ntop can be seen as a simple RMON-like agent with an embedded web interface. The use of:

  • a web interface
  • limited configuration and administration via the web interface
  • reduced CPU and memory usage (they vary according to network size and traffic)

make ntop easy to use and suitable for monitoring various kind of networks.

In an effort to encourage use of the Untangle forums, I’ve posted a online how to at: http://forums.untangle.com. Please post comments and feedback on the Untangle thread.

Country IP Blocking

Country IP Blocks provides an online, search able internet protocol (IP) address database with the ability to export specific country level IP blocks into CIDR, Netmask, IP Range, .htaccess deny, .htaccess allow, Decimal/CIDR and Hex/CIDR formatted files. These files can then be used in cojunction with server (e.g. Apache, Microsoft IIS) and network security devices (e.g. Cisco, Juniper, TippingPoint, Untangle) to create access control lists to block access to networks and systems from specific countries.

Whilst I don’t advocate blocking entire countries, there are known IP address blocks used by spammers, crackers and other Internet filth which may need to be blocked from some websites and systems.

The American Registry for Internet Numbers (ARIN) and the Asia Pacific Network Information Centre (APNIC) manage the majority of Internet routed IP addresses allocations for IP v4 and maintain online allocation databases which are made available to Internet service providers. The Country IP database is updated with this information at least once every 24 hours which means accurate global network data is provided.

In terms of Country IP Blocks site, I specifically like the ability to export IP lists into common access control list formats such as HTACCESS. A simple example Continue reading “Country IP Blocking”