Hello all.
I'm getting reports which show huge traffic amounts on some http IP 
addresses. These point to ports like 9000, 8000, 8100, 9720, and the 
like. When I put those URLs in the browser, I get to some shoutcast 
servers (let's take as an example: http://213.35.156.16:9000/). How may 
I block this sort of streaming media?
Here the relevant log lines:
1131956633.216   7236 10.167.211.62 TCP_MISS/600 298294 GET 
http://213.35.156.16:9000/ - 
FIRST_PARENT_MISS/proxy.reteunitaria.piemonte.it -
1131965732.540    917 10.167.211.62 TCP_MISS/600 25021 GET 
http://213.35.156.16:9000/ - 
FIRST_PARENT_MISS/proxy.reteunitaria.piemonte.it -
1131965815.003  81204 10.167.211.62 TCP_MISS/600 2093292 GET 
http://213.35.156.16:9000/ - 
TIMEOUT_FIRST_UP_PARENT/proxy.reteunitaria.piemonte.it -
1131982736.548   6082 10.167.211.62 TCP_MISS/600 362948 GET 
http://213.35.156.16:9000/ - 
TIMEOUT_FIRST_UP_PARENT/proxy.reteunitaria.piemonte.it -
1131985079.527   2613 10.167.211.62 TCP_MISS/600 163257 GET 
http://213.35.156.16:8000/ - 
FIRST_PARENT_MISS/proxy.reteunitaria.piemonte.it -
1131985825.545   2244 10.167.211.62 TCP_MISS/600 106951 GET 
http://213.35.156.16:9000/ - 
FIRST_PARENT_MISS/proxy.reteunitaria.piemonte.it -
1131986644.367 7009798 10.167.211.163 TCP_MISS/600 168504426 GET 
http://213.35.156.16:8000/ - 
FIRST_PARENT_MISS/proxy.reteunitaria.piemonte.it -
As you can see, there's nothing more than the URL, no MIME type 
indication at all!
Any help would be appreciated.
Thanks in advance,
-- ----------------------------------- Boniforti Flavio Provincia del Verbano-Cusio-Ossola Ufficio Informatica Tecnoparco del Lago Maggiore Via dell'Industria, 25 28924 Verbania -----------------------------------Received on Tue Nov 15 2005 - 07:55:17 MST
This archive was generated by hypermail pre-2.1.9 : Thu Dec 01 2005 - 12:00:09 MST