Thanks, Sven.  In short, I'm simply looking for an ntop-like solution that has the capability to look at flows on all ports, rather than application protocols.  For example, when running the application, I would be able to look at inbound vs outbound packets associated with each port.  Also, it would have to be able to write the data for later historical analysis.  Does this mimic your solution?

-BP

Sven Anderson <[EMAIL PROTECTED]> wrote:
Hi Ben,

Ben Paradis, 17.04.2006 16:05:
> * What do you precisely mean by "port" ? Physical port, IP address,
> MAC address, etc.
> A. By port I mean the endpoint for the logical connection, such as port
> 80, 443 etc. We would like to understand which ports are being used the
> most, which is a complicated task because there are over 65000 ports to
> observe.

This sounds like you might be interested in the simple Flow Explorer I'm
writing at the moment, which can sum up arbitrary counters grouped by an
arbitrary Flow Key, optionally in a subspace of the flow data defined by
certain Flow Key values. Just give me 2 more weeks and I'll release a
first version.


Cheers,

Sven

--
Sven Anderson
Institute for Informatics - http://www.ifi.informatik.uni-goettingen.de
Georg-August-Universitaet Goettingen
Lotzestr. 16-18, 37083 Goettingen, Germany

_______________________________________________
pmacct-discussion mailing list
http://www.pmacct.net/#mailinglists


Yahoo! Messenger with Voice. PC-to-Phone calls for ridiculously low rates.
_______________________________________________
pmacct-discussion mailing list
http://www.pmacct.net/#mailinglists

Reply via email to