Traffic Trace Info


DumpFile: 201001171400.dump
FileSize: 1280.05MB
Id: 201001171400
StartTime: Sun Jan 17 14:00:01 2010
EndTime: Sun Jan 17 14:15:00 2010
TotalTime: 899.85 seconds
TotalCapSize: 999.93MB CapLen: 96 bytes
# of packets: 18357549 (12516.71MB)
AvgRate: 116.68Mbps stddev:16.02M

IP flow (unique src/dst pair) Information

# of flows: 847619 (avg. 21.66 pkts/flow)
Top 10 big flow size (bytes/total in %):
2.1% 1.8% 1.7% 1.7% 1.6% 1.6% 1.5% 1.4% 1.3% 1.2%

IP address Information

# of IPv4 addresses: 502197
Top 10 bandwidth usage (bytes/total in %):
24.9% 4.0% 3.4% 2.6% 2.6% 2.2% 2.2% 2.1% 1.8% 1.8%
# of IPv6 addresses: 831
Top 10 bandwidth usage (bytes/total in %):
14.4% 7.4% 6.5% 6.3% 5.8% 5.8% 5.6% 5.3% 4.6% 4.0%

Packet Size Distribution (including MAC headers)

[packet size distribution]
detailed numbers
 [   32-   63]:    3869331
 [   64-  127]:    4540500
 [  128-  255]:     823772
 [  256-  511]:     445982
 [  512- 1023]:     444809
 [ 1024- 2047]:    8233155


Protocol Breakdown

[protocol breakdown chart]

     protocol		packets			bytes		bytes/pkt
------------------------------------------------------------------------
 total         18357549 (100.00%)      13124723944 (100.00%)    714.95
 ip            18334802 ( 99.88%)      13120661740 ( 99.97%)    715.62
  tcp          14244583 ( 77.60%)      11457134239 ( 87.29%)    804.32
   http(s)      4455654 ( 24.27%)       5905264414 ( 44.99%)   1325.34
   http(c)      2904365 ( 15.82%)        271043599 (  2.07%)     93.32
   squid         421148 (  2.29%)        112280587 (  0.86%)    266.61
   smtp          146696 (  0.80%)         34561565 (  0.26%)    235.60
   nntp           41981 (  0.23%)          2548786 (  0.02%)     60.71
   ftp            33768 (  0.18%)          8863793 (  0.07%)    262.49
   pop3           13741 (  0.07%)         11150482 (  0.08%)    811.48
   imap           12977 (  0.07%)         16477597 (  0.13%)   1269.75
   telnet          3281 (  0.02%)           401575 (  0.00%)    122.39
   ssh           256929 (  1.40%)         31111815 (  0.24%)    121.09
   dns            46006 (  0.25%)          6644038 (  0.05%)    144.42
   bgp              127 (  0.00%)            33054 (  0.00%)    260.27
   napster           84 (  0.00%)            10374 (  0.00%)    123.50
   realaud           20 (  0.00%)             5945 (  0.00%)    297.25
   rtsp           14841 (  0.08%)         21642702 (  0.16%)   1458.30
   icecast          255 (  0.00%)            20654 (  0.00%)     81.00
   other        5892703 ( 32.10%)       5035072839 ( 38.36%)    854.46
  udp           3186301 ( 17.36%)       1283589631 (  9.78%)    402.85
   dns          1059041 (  5.77%)        141337538 (  1.08%)    133.46
   realaud          923 (  0.01%)            56735 (  0.00%)     61.47
   halflif          134 (  0.00%)            12154 (  0.00%)     90.70
   starcra          169 (  0.00%)            27118 (  0.00%)    160.46
   everque          150 (  0.00%)            33472 (  0.00%)    223.15
   unreal           151 (  0.00%)            25160 (  0.00%)    166.62
   quake             46 (  0.00%)             6606 (  0.00%)    143.61
   cuseeme           10 (  0.00%)              915 (  0.00%)     91.50
   other        2125607 ( 11.58%)       1142030358 (  8.70%)    537.27
  icmp           465936 (  2.54%)         35119849 (  0.27%)     75.37
  ipip              356 (  0.00%)            47308 (  0.00%)    132.89
  ipsec            9058 (  0.05%)          3814804 (  0.03%)    421.15
  ip6            427614 (  2.33%)        340838983 (  2.60%)    797.07
  other             954 (  0.01%)           116926 (  0.00%)    122.56
  frag            12750 (  0.07%)         10196178 (  0.08%)    799.70
 ip6              22747 (  0.12%)          4062204 (  0.03%)    178.58
  tcp6             6730 (  0.04%)           849290 (  0.01%)    126.19
   http(s)         1432 (  0.01%)           253286 (  0.00%)    176.88
   http(c)         3698 (  0.02%)           339058 (  0.00%)     91.69
   squid              1 (  0.00%)               86 (  0.00%)     86.00
   smtp              60 (  0.00%)            23576 (  0.00%)    392.93
   ftp               26 (  0.00%)             2181 (  0.00%)     83.88
   ssh               25 (  0.00%)             2822 (  0.00%)    112.88
   dns              515 (  0.00%)           132507 (  0.00%)    257.30
   bgp              107 (  0.00%)            13191 (  0.00%)    123.28
   other            866 (  0.00%)            82583 (  0.00%)     95.36
  udp6            12362 (  0.07%)          2765623 (  0.02%)    223.72
   dns            12341 (  0.07%)          2763353 (  0.02%)    223.92
   other             21 (  0.00%)             2270 (  0.00%)    108.10
  icmp6            3596 (  0.02%)           412997 (  0.00%)    114.85
  pim6               30 (  0.00%)             4080 (  0.00%)    136.00
  other6             29 (  0.00%)            30214 (  0.00%)   1041.86


tcpdump file: 201001171400.dump.gz (456.40 MB)