ntop recording traffic as FTP
so I have some custom stuff running on some custom ports and I've added them to the ntop protocol.list, but when the client is running, all the traffic is getting categorized as FTP traffic. I'm not sure whats going on because netstat shows the traffic as being on the 49xxx ports, external inspection shows the clients are connecting to the 49xxx ports, but ntop still says its FTP. iptables is even blocking FTP... anyone have any thoughts?
additionally, ntop shows lots of NetBIOS and other random traffic (probably from other clients) but I should be dropping all that at the iptables level. I even have a few custom rules to suppress Windows-related broadcast traffic.
thanks in advance,