We are getting flooded from and internal source by what I can only
presume
is a virus with a SMTP engine, everytime I unblock port 25 our
internet
connection goes crazy.
My question is this, how can I tell what IP address the traffic is
coming
from so that I go kill it? We have no packet tracing tools here.

Thanks,

--
Matt Hudson,
Principle Network and Communications Officer,
Burnley Borough Council.
CNA 6/5/4, CNE 5/4.