Help! Monitor Outgoing Traffic

Hi,
We colocate our server at a facility and today we got an email saying that our server appears to be sending bad traffic or pinging another server in the same colocation facility. How can we monitor our servers outgoing traffic to see that this is actually happening and someone is not just spoofing our ip. The people with the other server are threatning us with a lawsuit saying we are bringing down their servers so we need to get this sorted.

Below is an exerpt they say is from the firewall log showing our ip 216.158.96.207 giving them problems.


SonicWALL 0040-1012-812B Log (part 1) dumped to email at 07/29/2003 17:27:54.800
07/29/2003 17:05:15.672 - Log successfully sent via email
07/29/2003 17:06:35.272 - UDP packet dropped -
Source:216.158.96.207, 54260, WAN - Destination:10.2.0.109, 53, LAN
-
-
07/29/2003 17:08:23.528 - UDP packet dropped -
Source:216.158.96.207, 54265, WAN - Destination:10.2.0.109, 53, LAN
-
-
07/29/2003 17:09:25.144 - Problem sending log email; check log
settings
07/29/2003 17:11:19.160 - UDP packet dropped -
Source:216.158.96.207, 54282, WAN - Destination:10.2.0.109, 53, LAN
-
-
07/29/2003 17:12:22.720 - UDP packet dropped -
Source:216.158.96.207, 54290, WAN - Destination:10.2.0.109, 53, LAN
-
-
07/29/2003 17:13:51.608 - UDP packet dropped -
Source:216.158.96.207, 54304, WAN - Destination:10.2.0.109, 53, LAN
-
-
07/29/2003 17:18:44.416 - Successful administrator login -
Source:10.2.0.101, LAN - Destination:10.2.0.254, LAN - -
07/29/2003 17:18:58.752 - UDP packet dropped -
Source:216.158.96.207, 54311, WAN - Destination:10.2.0.109, 53, LAN
-
-
07/29/2003 17:21:57.112 - ICMP packet dropped -
Source:130.15.248.31, 4, WAN - Destination:10.2.0.108, LAN - 'Source
Quench' - Rule 12
07/29/2003 17:22:30.896 - UDP packet dropped -
Source:216.158.96.207, 54321, WAN - Destination:10.2.0.109, 53, LAN
-
-
07/29/2003 17:23:55.736 - UDP packet dropped -
Source:216.158.96.207, 54330, WAN - Destination:10.2.0.109, 53, LAN
-
-
07/29/2003 17:25:41.640 - UDP packet dropped -
Source:216.158.96.207, 54342, WAN - Destination:10.2.0.109, 53, LAN
-
-
07/29/2003 17:27:29.352 - Successful administrator login -
Source:10.2.0.101, LAN - Destination:10.2.0.254, LAN - -
07/29/2003 17:27:52.624 - Successful administrator login -
Source:10.2.0.101, LAN - Destination:10.2.0.254, LAN - -

Any advice would be greatly appreciated.

Thanks.

 

 

 

 

Top