Wireshark and GeoIP, now you’ll know where traffic is coming from.
How would you like to see where the traffic is coming from that is getting onto your network? How about what Autonomous System? Would you like to be able to filter on any of those fields? Wireshark lets you just that for both IPv4 and IPv6 addresses. All you have to do is download the databases from MaxMind and configure Wireshark to use them. Here are the steps:
First you’ll need to download the databases from http://dev.maxmind.com/geoip/legacy/geolite/. MaxMind distributes these for free and gets their information from ARIN. Be sure to download from the binary/gzip column, highlighted in red below. Wireshark cannot read csv files.