Excuse in the preceding topic I wrote bad ip address.

I've installed an ntop3.2rc using the rpm ntop-3.2rc2_centos41-1 and 
it's running on a linux server with OS centOS 4.4 and linux kernel 
2.6.9-42.0.10.EL-i686. 
I want see the host's traffic of a subnet who I can see with the eth1.

Using tcpdump I can see the different hosts of the subnet 10.127.0.0
/24
Using ntop in this way:
/usr/bin/ntop -P /usr/share/ntop -u ntop -i eth1 -d -B "net 10.127.0.0
/16" -m 10.127.0.0/16 --sticky-hosts

I can see only a little part of this hosts
For example if I see with the tcpdump the traffic of the host 
10.127.11.14 with port 1050
10.127.10.20 with port 1080
10.127.14.25 with port 1090
10.127.12.34 with port 1120

using ntop I see only one host with the ports of the 4 different hosts
10.127.11.14 with port 1050, 1080, 1090, 1120

Why I see a traffic aggregate and not the details of the local traffic?


Naviga e telefona senza limiti con Tiscali     
Scopri le promozioni Tiscali adsl: navighi e telefoni senza canone Telecom

http://abbonati.tiscali.it/adsl/

_______________________________________________
Ntop mailing list
Ntop@unipi.it
http://listgateway.unipi.it/mailman/listinfo/ntop

Reply via email to