Hi,

I have 3 closely related issues.  

1) I really like IP Protos -> Sessions table.  I just wish it were
possible to sort by columns there.

2) My network is behind a firewall, and I don't allow http out.  All
browing goes through a proxy.  Real Player in default installation
tries to send data to http port on chanrr1.real.com once in a while
(down with spyware!!) and those packets get dropped.  However, for at
least 20 minutes after a packet got dropped, there's a listing in IP
Protos -> Sessions table like this:


172.17.0.208:1391
                 chanrr1.real.com:http
                                      248
                                         0
                                          02/22/02 13:10:16
                                                           02/22/02 13:10:37
                                                                            5:07

The 3rd and 4th column indicate that a small packet was dropped.  The last
column shows the age of the pseudo-connection, 5min in this case.  
I believe it's a bug.  I'm using Feb 15 snapshot on RH-7.2 machine, and
all traffic is mirror to a port on a switch level.

3) After a certain period of inactivity, a host disapears from the list.
When it's active again and reappears, the traffic counter starts from zero.
IIRC, stable version didn't behave like that, and I was able to accumulate
traffic statistics for host over a few day period.  Is it a bug or a feature
in development version?  I see some merit on both behaviors, so I think it'd
be useful to be able to flip between them with a flag.

Thanks

Igor
_______________________________________________
Ntop mailing list
[EMAIL PROTECTED]
http://listmanager.unipi.it/mailman/listinfo/ntop

Reply via email to