LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 02-12-2013, 11:18 AM   #1
seabro
LQ Newbie
 
Registered: Jan 2010
Posts: 26

Rep: Reputation: 0
TCPDUMP Question


Hi,

On my LAN, MRTG is showing high utilisation of the Internet link in the upstream direction. In fact it is constantly maxed out at 690kb/s.

I have a tcpdump of the traffic on the WAN port of the switch and my question is, how can I analyse the tcpdump file to find out who is maxing out the upstream link?

We have 8mb/s down and 700kb/s up and down is running at 350kb/s and up is maxed out at 690kb/s.

Any assistance greatly appreciated.

seabro
 
Old 02-12-2013, 12:00 PM   #2
jlinkels
LQ Guru
 
Registered: Oct 2003
Location: Bonaire, Leeuwarden
Distribution: Debian /Jessie/Stretch/Sid, Linux Mint DE
Posts: 5,195

Rep: Reputation: 1043Reputation: 1043Reputation: 1043Reputation: 1043Reputation: 1043Reputation: 1043Reputation: 1043Reputation: 1043
I don't think TCPdump is the right tool for that. jnettop shows traffic sorted by bitrate and usually proves me useful for these kind of mysteries. Once you know which host/port causes the traffic, TCPdump comes into picture to analyse the data itself if it is still a mystery.

There are other similar tools like jnettop in case you can't install that.

jlinkels
 
Old 02-12-2013, 12:12 PM   #3
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
There's a few command line tools that may help like tcpflow, tcptrace, tcpstat (output example), etc, etc but if you're familiar with Wireshark it's good to know it can show a packet capture breakdown (menu > statistics > protocol hierarchy) so you can see if the majority is TCP or UDP or something else, what remote ports are used, etc ,etc. Apply a filter for the protocol and remote port (example: tcp.port == 20) and you'll see what the LAN source IP is.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
tcpdump question skoinga Linux - Networking 5 10-28-2010 01:32 PM
Tcpdump question? chinmays Linux - Software 9 01-08-2006 08:56 PM
tcpdump question gauge73 Linux - Newbie 2 08-09-2005 04:37 PM
tcpdump -n question Melissa22 Linux - Networking 3 03-07-2004 08:05 PM
tcpdump question Xris718 Linux - Networking 1 12-08-2003 11:42 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 07:56 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration