Page 1 of 1

eDonkey P2P Alerts from IPS

Posted: Wed Feb 19, 2014 2:18 pm
by jeffersjw
I block P2P on my network and suddenly am getting alerts from my IPS about the Nagios XI server, any ideas?

SN=380030171 app="eDonkey" app_cat="P2P" user="N/A" group="N/A" msg="N/A" carrier_ep="N/A" profilegroup="N/A" subapp="eDonkey" subappcat="P2P

Re: eDonkey P2P Alerts from IPS

Posted: Wed Feb 19, 2014 3:49 pm
by tmcdonald
Nagios doesn't do anything with the P2P protocol, and certainly not eDonkey. I would take a look at your security logs, sounds like your server might be getting utilized for torrenting. tcpdump and ps are your friends here.