Traffic Trace Info


DumpFile: 201004131815.dump
FileSize: 2412.93MB
Id: 201004131815
StartTime: Tue Apr 13 18:15:01 2010
EndTime: Tue Apr 13 18:30:00 2010
TotalTime: 899.54 seconds
TotalCapSize: 1885.25MB CapLen: 96 bytes
# of packets: 34580568 (23154.33MB)
AvgRate: 215.95Mbps stddev:22.92M

IP flow (unique src/dst pair) Information

# of flows: 1114723 (avg. 31.02 pkts/flow)
Top 10 big flow size (bytes/total in %):
1.3% 1.1% 0.9% 0.8% 0.8% 0.8% 0.7% 0.6% 0.5% 0.5%

IP address Information

# of IPv4 addresses: 588348
Top 10 bandwidth usage (bytes/total in %):
14.1% 6.8% 6.8% 6.1% 5.6% 5.3% 2.3% 2.3% 2.0% 1.7%
# of IPv6 addresses: 1095
Top 10 bandwidth usage (bytes/total in %):
23.2% 7.6% 6.2% 5.2% 5.1% 5.0% 4.9% 4.9% 3.4% 3.4%

Packet Size Distribution (including MAC headers)

[packet size distribution]
detailed numbers
 [   32-   63]:    6021012
 [   64-  127]:    8444918
 [  128-  255]:    2402012
 [  256-  511]:    1886111
 [  512- 1023]:     999895
 [ 1024- 2047]:   14826620


Protocol Breakdown

[protocol breakdown chart]

     protocol		packets			bytes		bytes/pkt
------------------------------------------------------------------------
 total         34580568 (100.00%)      24279079550 (100.00%)    702.10
 ip            34526472 ( 99.84%)      24269782444 ( 99.96%)    702.93
  tcp          22143009 ( 64.03%)      17871262341 ( 73.61%)    807.08
   http(s)      9705087 ( 28.07%)      13245102115 ( 54.55%)   1364.76
   http(c)      6121390 ( 17.70%)        912861460 (  3.76%)    149.13
   squid         305048 (  0.88%)        102754864 (  0.42%)    336.85
   smtp          504530 (  1.46%)        175605923 (  0.72%)    348.06
   ftp            33915 (  0.10%)          3241131 (  0.01%)     95.57
   pop3           13214 (  0.04%)          4968451 (  0.02%)    376.00
   imap            6914 (  0.02%)           639131 (  0.00%)     92.44
   telnet           979 (  0.00%)            83647 (  0.00%)     85.44
   ssh           261212 (  0.76%)         37985703 (  0.16%)    145.42
   dns            53347 (  0.15%)          3676429 (  0.02%)     68.92
   bgp              149 (  0.00%)            51002 (  0.00%)    342.30
   napster           59 (  0.00%)            10290 (  0.00%)    174.41
   realaud           55 (  0.00%)             3550 (  0.00%)     64.55
   rtsp          178254 (  0.52%)         38523676 (  0.16%)    216.12
   icecast          797 (  0.00%)            60639 (  0.00%)     76.08
   hotline            7 (  0.00%)              840 (  0.00%)    120.00
   other        4958036 ( 14.34%)       3345692530 ( 13.78%)    674.80
  udp           8579098 ( 24.81%)       4628808437 ( 19.07%)    539.54
   dns           930700 (  2.69%)        180857862 (  0.74%)    194.32
   realaud           81 (  0.00%)            14036 (  0.00%)    173.28
   halflif           60 (  0.00%)             6738 (  0.00%)    112.30
   starcra          192 (  0.00%)            18486 (  0.00%)     96.28
   everque         2247 (  0.01%)           362722 (  0.00%)    161.43
   unreal           195 (  0.00%)            32879 (  0.00%)    168.61
   quake            118 (  0.00%)            16799 (  0.00%)    142.36
   cuseeme           11 (  0.00%)             1146 (  0.00%)    104.18
   other        7645099 ( 22.11%)       4447290833 ( 18.32%)    581.72
  icmp           803199 (  2.32%)         88536354 (  0.36%)    110.23
  ipip              346 (  0.00%)            42664 (  0.00%)    123.31
  ipsec            1400 (  0.00%)           460832 (  0.00%)    329.17
  ip6           2943194 (  8.51%)       1672094685 (  6.89%)    568.12
  other           56226 (  0.16%)          8577131 (  0.04%)    152.55
  frag             2134 (  0.01%)          2228972 (  0.01%)   1044.50
 ip6              54096 (  0.16%)          9297106 (  0.04%)    171.86
  tcp6            16346 (  0.05%)          2063466 (  0.01%)    126.24
   http(s)          473 (  0.00%)           422025 (  0.00%)    892.23
   http(c)         5029 (  0.01%)           466067 (  0.00%)     92.68
   smtp             266 (  0.00%)           123771 (  0.00%)    465.30
   ftp             2666 (  0.01%)           277032 (  0.00%)    103.91
   imap             260 (  0.00%)            29855 (  0.00%)    114.83
   ssh             3194 (  0.01%)           270696 (  0.00%)     84.75
   dns              112 (  0.00%)            28928 (  0.00%)    258.29
   bgp              117 (  0.00%)            16177 (  0.00%)    138.26
   other           4229 (  0.01%)           428915 (  0.00%)    101.42
  udp6            31464 (  0.09%)          6413595 (  0.03%)    203.84
   dns            30935 (  0.09%)          6324711 (  0.03%)    204.45
   other            529 (  0.00%)            88884 (  0.00%)    168.02
  icmp6            6190 (  0.02%)           751906 (  0.00%)    121.47
  pim6               30 (  0.00%)             4080 (  0.00%)    136.00
  other6             66 (  0.00%)            64059 (  0.00%)    970.59


tcpdump file: 201004131815.dump.gz (891.97 MB)