Traffic Trace Info


DumpFile: 201008141400.dump
FileSize: 1895.68MB
Id: 201008141400
StartTime: Sat Aug 14 14:00:00 2010
EndTime: Sat Aug 14 14:15:01 2010
TotalTime: 900.54 seconds
TotalCapSize: 1486.83MB CapLen: 96 bytes
# of packets: 26793631 (18064.37MB)
AvgRate: 168.26Mbps stddev:17.99M

IP flow (unique src/dst pair) Information

# of flows: 685598 (avg. 39.08 pkts/flow)
Top 10 big flow size (bytes/total in %):
5.9% 2.2% 1.7% 1.5% 1.2% 1.0% 0.9% 0.9% 0.9% 0.8%

IP address Information

# of IPv4 addresses: 383224
Top 10 bandwidth usage (bytes/total in %):
16.8% 10.3% 8.9% 7.3% 6.1% 3.3% 2.3% 2.2% 2.2% 2.1%
# of IPv6 addresses: 1862
Top 10 bandwidth usage (bytes/total in %):
43.6% 43.6% 14.9% 14.9% 8.9% 8.4% 6.0% 6.0% 4.1% 3.9%

Packet Size Distribution (including MAC headers)

[packet size distribution]
detailed numbers
 [   32-   63]:    3846611
 [   64-  127]:    7206960
 [  128-  255]:    1771478
 [  256-  511]:    1436730
 [  512- 1023]:     739701
 [ 1024- 2047]:   11792151


Protocol Breakdown

[protocol breakdown chart]

     protocol		packets			bytes		bytes/pkt
------------------------------------------------------------------------
 total         26793631 (100.00%)      18941860898 (100.00%)    706.95
 ip            26647692 ( 99.46%)      18873595223 ( 99.64%)    708.26
  tcp          15785957 ( 58.92%)      13104493669 ( 69.18%)    830.14
   http(s)      6833269 ( 25.50%)       9310623882 ( 49.15%)   1362.54
   http(c)      3698344 ( 13.80%)        536404416 (  2.83%)    145.04
   squid         216235 (  0.81%)        107552859 (  0.57%)    497.39
   smtp          198734 (  0.74%)         46969527 (  0.25%)    236.34
   nntp              11 (  0.00%)              700 (  0.00%)     63.64
   ftp            22853 (  0.09%)          2140655 (  0.01%)     93.67
   pop3            5111 (  0.02%)          2463608 (  0.01%)    482.02
   imap            3347 (  0.01%)           833744 (  0.00%)    249.10
   telnet          1060 (  0.00%)            70601 (  0.00%)     66.60
   ssh           853116 (  3.18%)        414619036 (  2.19%)    486.01
   dns             3676 (  0.01%)           340283 (  0.00%)     92.57
   bgp              155 (  0.00%)            58469 (  0.00%)    377.22
   napster            2 (  0.00%)              122 (  0.00%)     61.00
   realaud           22 (  0.00%)             1769 (  0.00%)     80.41
   rtsp             262 (  0.00%)            73756 (  0.00%)    281.51
   icecast          766 (  0.00%)            51254 (  0.00%)     66.91
   hotline          244 (  0.00%)            15257 (  0.00%)     62.53
   other        3948748 ( 14.74%)       2682273611 ( 14.16%)    679.27
  udp           7513577 ( 28.04%)       4030605147 ( 21.28%)    536.44
   dns           659940 (  2.46%)        120072595 (  0.63%)    181.94
   realaud         1816 (  0.01%)           110079 (  0.00%)     60.62
   halflif           48 (  0.00%)             4532 (  0.00%)     94.42
   starcra           73 (  0.00%)            12834 (  0.00%)    175.81
   everque          585 (  0.00%)           108359 (  0.00%)    185.23
   unreal            40 (  0.00%)             4331 (  0.00%)    108.28
   quake           1411 (  0.01%)          1013495 (  0.01%)    718.28
   cuseeme            3 (  0.00%)              262 (  0.00%)     87.33
   other        6849456 ( 25.56%)       3909154131 ( 20.64%)    570.72
  icmp           423294 (  1.58%)         43101873 (  0.23%)    101.82
  ipip              346 (  0.00%)            40280 (  0.00%)    116.42
  ipsec             443 (  0.00%)            91146 (  0.00%)    205.75
  ip6           2923024 ( 10.91%)       1695092714 (  8.95%)    579.91
  other            1051 (  0.00%)           170394 (  0.00%)    162.13
  frag            17483 (  0.07%)         14260935 (  0.08%)    815.70
 ip6             145939 (  0.54%)         68265675 (  0.36%)    467.77
  tcp6            68286 (  0.25%)         30812751 (  0.16%)    451.23
   http(s)         1240 (  0.00%)          1394624 (  0.01%)   1124.70
   http(c)         1393 (  0.01%)           188645 (  0.00%)    135.42
   squid             56 (  0.00%)             5264 (  0.00%)     94.00
   smtp              73 (  0.00%)             8983 (  0.00%)    123.05
   imap             323 (  0.00%)            36683 (  0.00%)    113.57
   dns              223 (  0.00%)            26310 (  0.00%)    117.98
   bgp              121 (  0.00%)            16643 (  0.00%)    137.55
   icecast           28 (  0.00%)             2632 (  0.00%)     94.00
   other          64829 (  0.24%)         29132967 (  0.15%)    449.38
  udp6            30808 (  0.11%)          6691262 (  0.04%)    217.19
   dns            11997 (  0.04%)          2821299 (  0.01%)    235.17
   halflif            1 (  0.00%)              110 (  0.00%)    110.00
   starcra           79 (  0.00%)             7240 (  0.00%)     91.65
   other          18731 (  0.07%)          3862613 (  0.02%)    206.21
  icmp6            4234 (  0.02%)           806684 (  0.00%)    190.53
  pim6               30 (  0.00%)             4080 (  0.00%)    136.00
  other6          42581 (  0.16%)         29950898 (  0.16%)    703.39


tcpdump file: 201008141400.dump.gz (681.11 MB)