-
Notifications
You must be signed in to change notification settings - Fork 36
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Large network traffic detected on HOPOPT/0 to port 0 #56
Comments
Looks like IP-in-IP tunnel traffic? |
@jow- Thanks for replying So it is another kind of IP-in-IP traffic? There's an item in protocol mapping writes |
Not sure, could also mean "no layer 4 protocol information available". You didn't provide any details about the setup you run the service on, but maybe your firewall setup is unusual. Compare with |
Okay, I'll do some further examination on that file later since I haven't found anything missing layer 4 protocol yet. |
After some experiments, I notice that the HOPOPT traffic is mainly caused by torrent downloading. And the connection information looks like
in |
When grouped the data by protocols, I found the following traffic ranged at the top
According to
/etc/protocols
the No.1 traffic is protocol IP or HOPOPT.I wonder what kind of traffic it exactly is and what it should be classified in layer7 column?
The text was updated successfully, but these errors were encountered: