Traffic Trace Info


DumpFile: 201211071400.dump
FileSize: 3952.99MB
Id: 201211071400
StartTime: Wed Nov 7 14:00:01 2012
EndTime: Wed Nov 7 14:15:00 2012
TotalTime: 899.59 seconds
TotalCapSize: -994.05MB CapLen: 96 bytes
# of packets: 55772982 (25617.64MB)
AvgRate: 238.96Mbps stddev:35.67M

IP flow (unique src/dst pair) Information

# of flows: 12657953 (avg. 4.41 pkts/flow)
Top 10 big flow size (bytes/total in %):
3.7% 2.3% 1.9% 1.6% 1.6% 1.5% 1.4% 1.2% 1.2% 1.2%

IP address Information

# of IPv4 addresses: 9792575
Top 10 bandwidth usage (bytes/total in %):
11.1% 6.2% 5.7% 4.2% 4.0% 4.0% 4.0% 3.2% 3.1% 2.5%
# of IPv6 addresses: 9010
Top 10 bandwidth usage (bytes/total in %):
29.2% 20.9% 6.1% 3.1% 2.6% 2.5% 2.5% 2.1% 2.1% 2.1%

Packet Size Distribution (including MAC headers)

[packet size distribution]
detailed numbers
 [   32-   63]:   19454299
 [   64-  127]:   17396955
 [  128-  255]:    1099079
 [  256-  511]:     963018
 [  512- 1023]:    1026824
 [ 1024- 2047]:   15832807


Protocol Breakdown

[protocol breakdown chart]

     protocol		packets			bytes		bytes/pkt
------------------------------------------------------------------------
 total         55772982 (100.00%)      26862038538 (100.00%)    481.63
 ip            53508133 ( 95.94%)      24869709384 ( 92.58%)    464.78
  tcp          24345691 ( 43.65%)      21512433050 ( 80.08%)    883.62
   http(s)     13046162 ( 23.39%)      16532848113 ( 61.55%)   1267.26
   http(c)      6980250 ( 12.52%)       1461218009 (  5.44%)    209.34
   squid         253640 (  0.45%)         44528980 (  0.17%)    175.56
   smtp          204888 (  0.37%)        132057880 (  0.49%)    644.54
   nntp               3 (  0.00%)              180 (  0.00%)     60.00
   ftp            18583 (  0.03%)          3306418 (  0.01%)    177.93
   pop3            4555 (  0.01%)          2011586 (  0.01%)    441.62
   imap            6219 (  0.01%)          1184755 (  0.00%)    190.51
   telnet         59853 (  0.11%)          5898345 (  0.02%)     98.55
   ssh           168282 (  0.30%)         24883526 (  0.09%)    147.87
   dns             4177 (  0.01%)           456913 (  0.00%)    109.39
   bgp              610 (  0.00%)           154350 (  0.00%)    253.03
   napster           26 (  0.00%)             3590 (  0.00%)    138.08
   realaud           68 (  0.00%)             5081 (  0.00%)     74.72
   rtsp           36922 (  0.07%)         39339202 (  0.15%)   1065.47
   icecast        36676 (  0.07%)         30872861 (  0.11%)    841.77
   hotline           16 (  0.00%)             1355 (  0.00%)     84.69
   other        3524761 (  6.32%)       3233661906 ( 12.04%)    917.41
  udp           1798351 (  3.22%)        678338101 (  2.53%)    377.20
   dns           591254 (  1.06%)        200358297 (  0.75%)    338.87
   realaud           60 (  0.00%)            12437 (  0.00%)    207.28
   halflif           17 (  0.00%)             1794 (  0.00%)    105.53
   starcra           50 (  0.00%)             5640 (  0.00%)    112.80
   everque          169 (  0.00%)            24340 (  0.00%)    144.02
   unreal             4 (  0.00%)              405 (  0.00%)    101.25
   quake             26 (  0.00%)             2454 (  0.00%)     94.38
   cuseeme            6 (  0.00%)              412 (  0.00%)     68.67
   other        1206661 (  2.16%)        477848272 (  1.78%)    396.01
  icmp         25765443 ( 46.20%)       1655856146 (  6.16%)     64.27
  ipip              184 (  0.00%)            19160 (  0.00%)    104.13
  ipsec           50513 (  0.09%)          8284846 (  0.03%)    164.01
  ip6           1491033 (  2.67%)        996372092 (  3.71%)    668.24
  pim                16 (  0.00%)              960 (  0.00%)     60.00
  other           56902 (  0.10%)         18405029 (  0.07%)    323.45
  frag            88493 (  0.16%)         93833274 (  0.35%)   1060.35
 ip6            2264849 (  4.06%)       1992329154 (  7.42%)    879.67
  tcp6          2146733 (  3.85%)       1962904992 (  7.31%)    914.37
   http(s)      1766078 (  3.17%)       1896841596 (  7.06%)   1074.04
   http(c)       317768 (  0.57%)         34189936 (  0.13%)    107.59
   smtp            2223 (  0.00%)           745566 (  0.00%)    335.39
   ftp             1370 (  0.00%)          1007292 (  0.00%)    735.25
   pop3              19 (  0.00%)             4041 (  0.00%)    212.68
   imap             206 (  0.00%)            35456 (  0.00%)    172.12
   ssh               70 (  0.00%)            11684 (  0.00%)    166.91
   dns              263 (  0.00%)            45635 (  0.00%)    173.52
   bgp               94 (  0.00%)            21433 (  0.00%)    228.01
   other          58642 (  0.11%)         30002353 (  0.11%)    511.62
  udp6            90388 (  0.16%)         25024681 (  0.09%)    276.86
   dns            72088 (  0.13%)         21185231 (  0.08%)    293.88
   quake              1 (  0.00%)              116 (  0.00%)    116.00
   other          18299 (  0.03%)          3839334 (  0.01%)    209.81
  icmp6           26338 (  0.05%)          3138478 (  0.01%)    119.16
  ip6                84 (  0.00%)            11412 (  0.00%)    135.86
  pim6               30 (  0.00%)             4080 (  0.00%)    136.00
  other6           1276 (  0.00%)          1245511 (  0.00%)    976.11


tcpdump file: 201211071400.dump.gz (1202.64 MB)