Hello, In my ntop 2.2.91 report, under Total / TCP-UDP, I get a 13,2 Mb traffic in the "Other IP" column for 224.0.0.5 (OSPF multicast). When looking at the stats for this IP, it shows that 100% received traffic is OSPF, and the count is 13,2Mb.
Why is OSPF counted as "Other IP" in the TCP/UDP page ? I agree that OSPF is IP, but it isn't TCP nor UDP... I ran ntop with a "net 224.0.0.0/8" filter. OSPF trafic shows in "Total - All protocols - OSPF" (which is expected), "Total - TCP/UDP - Other IP" (which seems strange to me), and in "Stats - Traffic - Global protocol distribution" (but not as an unknown TCP/UDP prot. - which is also as expected). In the IP distribution graphs in the "info about host xxx.xxx.xxx.xxx" page, OSPF traffic is also shown as unknown (while it is properly shown as OSPF in the graph above, about Protocol distribution). If needed, I can provide screenshots and/or packet captures to reproduce this. I'd like to send them off-list, though. Lo�c _______________________________________________ Ntop-dev mailing list [EMAIL PROTECTED] http://listgateway.unipi.it/mailman/listinfo/ntop-dev
