Review your favorite Linux distribution.
Go Back > Forums > Linux Forums > Linux - Networking
User Name
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.


  Search this Thread
Old 02-12-2013, 12:18 PM   #1
LQ Newbie
Registered: Jan 2010
Posts: 26

Rep: Reputation: 0
TCPDUMP Question


On my LAN, MRTG is showing high utilisation of the Internet link in the upstream direction. In fact it is constantly maxed out at 690kb/s.

I have a tcpdump of the traffic on the WAN port of the switch and my question is, how can I analyse the tcpdump file to find out who is maxing out the upstream link?

We have 8mb/s down and 700kb/s up and down is running at 350kb/s and up is maxed out at 690kb/s.

Any assistance greatly appreciated.

Old 02-12-2013, 01:00 PM   #2
Senior Member
Registered: Oct 2003
Location: Bonaire
Distribution: Debian Wheezy/Jessie/Sid, Linux Mint DE
Posts: 4,487

Rep: Reputation: 627Reputation: 627Reputation: 627Reputation: 627Reputation: 627Reputation: 627
I don't think TCPdump is the right tool for that. jnettop shows traffic sorted by bitrate and usually proves me useful for these kind of mysteries. Once you know which host/port causes the traffic, TCPdump comes into picture to analyse the data itself if it is still a mystery.

There are other similar tools like jnettop in case you can't install that.

Old 02-12-2013, 01:12 PM   #3
Registered: May 2001
Posts: 28,898
Blog Entries: 55

Rep: Reputation: 3356Reputation: 3356Reputation: 3356Reputation: 3356Reputation: 3356Reputation: 3356Reputation: 3356Reputation: 3356Reputation: 3356Reputation: 3356Reputation: 3356
There's a few command line tools that may help like tcpflow, tcptrace, tcpstat (output example), etc, etc but if you're familiar with Wireshark it's good to know it can show a packet capture breakdown (menu > statistics > protocol hierarchy) so you can see if the majority is TCP or UDP or something else, what remote ports are used, etc ,etc. Apply a filter for the protocol and remote port (example: tcp.port == 20) and you'll see what the LAN source IP is.


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
tcpdump question skoinga Linux - Networking 5 10-28-2010 02:32 PM
Tcpdump question? chinmays Linux - Software 9 01-08-2006 09:56 PM
tcpdump question gauge73 Linux - Newbie 2 08-09-2005 05:37 PM
tcpdump -n question Melissa22 Linux - Networking 3 03-07-2004 09:05 PM
tcpdump question Xris718 Linux - Networking 1 12-09-2003 12:42 AM

All times are GMT -5. The time now is 01:43 AM.

Main Menu
Write for LQ is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Facebook: linuxquestions Google+: linuxquestions
Open Source Consulting | Domain Registration