⭐ 欢迎来到虫虫下载站! | 📦 资源下载 📁 资源专辑 ℹ️ 关于我们
⭐ 虫虫下载站

📄 lowerwin.html

📁 一个网络流量分析的完整的程序
💻 HTML
字号:
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN"><HTML><HEAD><TITLE>Lower Window</TITLE><METANAME="GENERATOR"CONTENT="Modular DocBook HTML Stylesheet Version 1.64"><LINKREL="HOME"TITLE="IPTraf User's Manual"HREF="manual.html"><LINKREL="UP"TITLE="The IP Traffic Monitor"HREF="itrafmon.html"><LINKREL="PREVIOUS"TITLE="The IP Traffic Monitor"HREF="itrafmon.html"><LINKREL="NEXT"TITLE="Additional Information"HREF="x1047.html"></HEAD><BODYCLASS="SECT1"BGCOLOR="#FFFFFF"TEXT="#000000"LINK="#0000FF"VLINK="#840084"ALINK="#0000FF"><DIVCLASS="NAVHEADER"><TABLEWIDTH="100%"BORDER="0"CELLPADDING="0"CELLSPACING="0"><TR><THCOLSPAN="3"ALIGN="center">IPTraf User's Manual</TH></TR><TR><TDWIDTH="10%"ALIGN="left"VALIGN="bottom"><AHREF="itrafmon.html">&#60;&#60;&#60; Previous</A></TD><TDWIDTH="80%"ALIGN="center"VALIGN="bottom">The IP Traffic Monitor</TD><TDWIDTH="10%"ALIGN="right"VALIGN="bottom"><AHREF="x1047.html">Next &#62;&#62;&#62;</A></TD></TR></TABLE><HRALIGN="LEFT"WIDTH="100%"></DIV><DIVCLASS="SECT1"><H1CLASS="SECT1"><ANAME="LOWERWIN">Lower Window</A></H1><P>  The lower window displays information about the other types of traffic  on your network. The following protocols are detected:</P><P></P><ULCOMPACT="COMPACT"><LI><P>User Datagram Protocol (UDP)</P></LI><LI><P>Internet Control Message Protocol (ICMP)</P></LI><LI><P>Open Shortest-Path First (OSPF)</P></LI><LI><P>Interior Gateway Routing Protocol (IGRP)</P></LI><LI><P>Interior Gateway Protocol (IGP)</P></LI><LI><P>Internet Group Management Protocol (IGMP)</P></LI><LI><P>General Routing Encapsulation (GRE)</P></LI><LI><P>Address Resolution Protocol (ARP)</P></LI><LI><P>Reverse Address Resolution Protocol (RARP)</P></LI></UL><P>  Unrecognized IP packets are indicated by their  protocol numbers while non-IP packets are indicated as<TTCLASS="COMPUTEROUTPUT">Non-IP</TT>  in the lower window.</P><DIVCLASS="NOTE"><P></P><TABLECLASS="NOTE"WIDTH="100%"BORDER="0"><TR><TDWIDTH="25"ALIGN="CENTER"VALIGN="TOP"><IMGSRC="./stylesheet-images/note.gif"HSPACE="5"ALT="Note"></TD><THALIGN="LEFT"VALIGN="CENTER"><B>Note</B></TH></TR><TR><TD>&nbsp;</TD><TDALIGN="LEFT"VALIGN="TOP"><P>The source and destination addresses for ARP andRARP entries are MAC addresses.</P><P>  Strictly speaking, ARP and RARP packets aren't IP packets, since  they are not encapsulated in an IP datagram. They're  just indicated because they are integral to proper IP operation on LANs.</P></TD></TR></TABLE></DIV><P>  For all packets in the lower window, only the first IP fragment is  indicated (since that contains the header  of the IP-encapsulated protocol) but with no further information  from the encapsulated protocol.</P><P>UDP packets are also displayedin<TTCLASS="COMPUTEROUTPUT"><TTCLASS="REPLACEABLE"><I>address</I></TT>:<TTCLASS="REPLACEABLE"><I>port</I></TT></TT> format while ICMP entries also contain theICMP message type. For easier location, each type of protocolis color-coded (only on color terminals such as the Linux console).</P><P></P><DIVCLASS="VARIABLELIST"><DL><DT>UDP</DT><DD><P>Red on White</P></DD><DT>ICMP</DT><DD><P>Yellow on Blue</P></DD><DT>OSPF</DT><DD><P>Black on Cyan</P></DD><DT>IGRP</DT><DD><P>Bright white on Cyan</P></DD><DT>IGP</DT><DD><P>Red on Cyan</P></DD><DT>IGMP</DT><DD><P>Bright green on Blue</P></DD><DT>GRE</DT><DD><P>Blue on white</P></DD><DT>ARP</DT><DD><P>Bright white on Red</P></DD><DT>RARP</DT><DD><P>Bright white on Red</P></DD><DT>Other IP</DT><DD><P>Yellow on red</P></DD><DT>Non-IP</DT><DD><P>Yellow on Red</P></DD></DL></DIV><P>  The lower window can hold up to 512 entries. You can  scroll the lower window by using the W key to move the Active indicator  to it, and by using the Up and Down cursor keys. The lower  window automatically scrolls every time a new entry is added, and either  the first entry or last entry is visible. Upon reaching 512 entries, old  entries are thrown out as new entries are added.</P><P>  Some entries may be too long to completely fit in a screen line. You can  use the Left and Right cursor keys to vertically scroll the lower window  when it is marked <TTCLASS="COMPUTEROUTPUT">Active</TT>.</P><P>  Entries for packets received on LAN interfaces also include the  source MAC address of the LAN host which delivered it. This behavior  is enabled by turning on the Source MAC addrs in traffic monitor toggle  in the <ICLASS="EMPHASIS"><AHREF="config.html">Configure...</A></I> menu.</P><DIVCLASS="SECT2"><H2CLASS="SECT2"><ANAME="AEN806">Entry Details</A></H2><P>  In general, the entries in the lower window indicate the protocol, the  IP datagram size (full frame size for non-IP, including ARP and  RARP), the source address, the destination  address, and the network interface the packet was detected on.  However, some protocols have a little more information.</P><DIVCLASS="SECT3"><H3CLASS="SECT3"><ANAME="AEN809">ICMP</A></H3><P>  ICMP entries are displayed in this format:</P><TABLEBORDER="0"BGCOLOR="#E0E0E0"WIDTH="100%"><TR><TD><PRECLASS="SYNOPSIS">ICMP <TTCLASS="REPLACEABLE"><I>type</I></TT> [(<TTCLASS="REPLACEABLE"><I>subtype</I></TT>)] (<TTCLASS="REPLACEABLE"><I>size</I></TT> bytes) from <TTCLASS="REPLACEABLE"><I>source</I></TT> to <TTCLASS="REPLACEABLE"><I>destination</I></TT>[(src HWaddr <TTCLASS="REPLACEABLE"><I>srcMACaddress</I></TT>)] on <TTCLASS="REPLACEABLE"><I>interface</I></TT></PRE></TD></TR></TABLE><P>  where type could be any of the following:</P><P></P><DIVCLASS="VARIABLELIST"><DL><DT><TTCLASS="COMPUTEROUTPUT">echo req, echo rply</TT></DT><DD><P>     ICMP echo request and reply. Usually used by the ping program and other network monitoring and diagnostic program. </P></DD><DT><TTCLASS="COMPUTEROUTPUT">dest unrch</TT></DT><DD><P>     ICMP destination unreachable. Something failed to reach its target. The dest unreach type is supplemented with a further indicator of the problem. Destination unreachable messages for TCP traffic causes the corresponding TCP entry in the upper     window to be made available for reuse by new connections. </P></DD><DT><TTCLASS="COMPUTEROUTPUT">redirct</TT></DT><DD><P>     ICMP redirect. Usually generated by a router to tell a host that a better gateway is available. </P></DD><DT><TTCLASS="COMPUTEROUTPUT">src qnch</TT></DT><DD><P>     The ICMP source quench is used to stop a host from transmitting. It's aflow control mechanism for IP. </P></DD><DT><TTCLASS="COMPUTEROUTPUT">time excd</TT></DT><DD><P>     Indicates a packet's time-to-live value expired before it gotto its destination. Mostly happens if a destination is too far away.Also used by the traceroute program.</P></DD><DT><TTCLASS="COMPUTEROUTPUT">router adv</TT></DT><DD><P>     ICMP router advertisement </P></DD><DT><TTCLASS="COMPUTEROUTPUT">router sol</TT></DT><DD><P>     ICMP router solicitation </P></DD><DT><TTCLASS="COMPUTEROUTPUT">timestmp req</TT></DT><DD><P>     ICMP timestamp request</P></DD><DT><TTCLASS="COMPUTEROUTPUT">timestmp rep</TT></DT><DD><P>     ICMP timestamp reply </P></DD><DT><TTCLASS="COMPUTEROUTPUT">info req</TT></DT><DD><P>     ICMP information request </P></DD><DT><TTCLASS="COMPUTEROUTPUT">info rep</TT></DT><DD><P>     ICMP information reply </P></DD><DT><TTCLASS="COMPUTEROUTPUT">addr mask req</TT></DT><DD><P>     ICMP address mask request </P></DD><DT><TTCLASS="COMPUTEROUTPUT">addr mask rep</TT></DT><DD><P>     ICMP address mask reply </P></DD><DT><TTCLASS="COMPUTEROUTPUT">param prob</TT></DT><DD><P>     ICMP parameter problem </P></DD><DT><TTCLASS="COMPUTEROUTPUT">bad/unknown</TT></DT><DD><P>     An unrecognized ICMP packet was received, or the packet is corrupted.</P></DD></DL></DIV><P>  The destination unreachable message also includes information on the  type of error encountered. Here are the destination unreachable codes:</P><P></P><DIVCLASS="VARIABLELIST"><DL><DT><TTCLASS="COMPUTEROUTPUT">ntwk</TT></DT><DD><P>     network unreachable </P></DD><DT><TTCLASS="COMPUTEROUTPUT">host</TT></DT><DD><P>     host unreachable </P></DD><DT><TTCLASS="COMPUTEROUTPUT">proto</TT></DT><DD><P>     protocol unreachable </P></DD><DT><TTCLASS="COMPUTEROUTPUT">port</TT></DT><DD><P>     port unreachable </P></DD><DT><TTCLASS="COMPUTEROUTPUT">pkt fltrd</TT></DT><DD><P>     packet filtered (normally by an access rule on a router or firewall) </P></DD><DT><TTCLASS="COMPUTEROUTPUT">DF set</TT></DT><DD><P>     the packet has to be fragmented somewhere, but its don't fragment     (DF) bit is set.</P></DD><DT><TTCLASS="COMPUTEROUTPUT">src rte fail</TT></DT><DD><P>     source route failed </P></DD><DT><TTCLASS="COMPUTEROUTPUT">src isltd</TT></DT><DD><P>     source isolated (obsolete) </P></DD><DT><TTCLASS="COMPUTEROUTPUT">net comm denied</TT></DT><DD><P>     network communication denied </P></DD><DT><TTCLASS="COMPUTEROUTPUT">host comm denied</TT></DT><DD><P>     host communication denied </P></DD><DT><TTCLASS="COMPUTEROUTPUT">net unrch for TOS</TT></DT><DD><P>     network unreachable for specified IP type-of-service </P></DD><DT><TTCLASS="COMPUTEROUTPUT">host unrch for TOS</TT></DT><DD><P>     host unreachable for specified IP type-of-service </P></DD><DT><TTCLASS="COMPUTEROUTPUT">prec violtn</TT></DT><DD><P>     precedence violation </P></DD><DT><TTCLASS="COMPUTEROUTPUT">prec cutoff</TT></DT><DD><P>     precedence cutoff </P></DD><DT><TTCLASS="COMPUTEROUTPUT">dest net unkn</TT></DT><DD><P>     destination network unknown </P></DD><DT><TTCLASS="COMPUTEROUTPUT">dest host unkn</TT></DT><DD><P>     destination network unknown</P></DD></DL></DIV><P>  For more information on ICMP, see RFC 792.</P></DIV><DIVCLASS="SECT3"><H3CLASS="SECT3"><ANAME="AEN980">OSPF</A></H3><P>OSPF messages also include a little more information. The format of anOSPF message in the window is:</P><TABLEBORDER="0"BGCOLOR="#E0E0E0"WIDTH="100%"><TR><TD><PRECLASS="SYNOPSIS">OSPF <TTCLASS="REPLACEABLE"><I>type</I></TT> (a=<TTCLASS="REPLACEABLE"><I>area</I></TT> r=<TTCLASS="REPLACEABLE"><I>router</I></TT>) (<TTCLASS="REPLACEABLE"><I>size</I></TT>bytes) from <TTCLASS="REPLACEABLE"><I>source</I></TT> to <TTCLASS="REPLACEABLE"><I>destination</I></TT>[(src HWaddr <TTCLASS="REPLACEABLE"><I>srcMACaddress</I></TT>)] on <TTCLASS="REPLACEABLE"><I>interface</I></TT></PRE></TD></TR></TABLE><P>  The type can be one of the following:</P><P></P><DIVCLASS="VARIABLELIST"><DL><DT><TTCLASS="COMPUTEROUTPUT">hlo</TT></DT><DD><P>     OSPF hello. Hello messages establish OSPF communications and keep routers informed of each other's presence. </P></DD><DT><TTCLASS="COMPUTEROUTPUT">DB desc</TT></DT><DD><P>     OSPF Database Description </P></DD><DT><TTCLASS="COMPUTEROUTPUT">LSR</TT></DT><DD><P>     OSPF Link State Request </P></DD><DT><TTCLASS="COMPUTEROUTPUT">LSU</TT></DT><DD><P>     OSPF Link State Update. Messages indicating the states of the OSPF network links </P></DD><DT><TTCLASS="COMPUTEROUTPUT">LSA</TT></DT><DD><P>     OSPF Link State Acknowledgment</P></DD></DL></DIV><P>  The entries in parentheses:</P><P></P><DIVCLASS="VARIABLELIST"><DL><DT><TTCLASS="COMPUTEROUTPUT">a=<TTCLASS="REPLACEABLE"><I>area</I></TT></TT></DT><DD><P>     The area number of the OSPF message</P></DD><DT><TTCLASS="COMPUTEROUTPUT">r=<TTCLASS="REPLACEABLE"><I>router</I></TT></TT></DT><DD><P>     The IP address of the router that generated the message. It     is not necessarily the same as the source address     of the encapsulating IP packet.</P></DD></DL></DIV><P>  Many times, the destination addresses for OSPF packets are class D  multicast addresses in standard dotted decimal notation or (if reverse  lookup is enabled), hosts under the <TTCLASS="COMPUTEROUTPUT">MCAST.NET</TT> domain. Such multicast  addresses are defined as follows:</P><P></P><DIVCLASS="VARIABLELIST"><DL><DT><TTCLASS="COMPUTEROUTPUT">224.0.0.5 (OSPF-ALL.MCAST.NET)</TT></DT><DD><P>OSPF all routers</P></DD><DT><TTCLASS="COMPUTEROUTPUT">224.0.0.6 (OSPF-DSIG.MCAST.NET)</TT></DT><DD><P>OSPF all designated routers</P></DD></DL></DIV><P>  See RFC 1247 for details on the OSPF protocol.</P></DIV></DIV></DIV><DIVCLASS="NAVFOOTER"><HRALIGN="LEFT"WIDTH="100%"><TABLEWIDTH="100%"BORDER="0"CELLPADDING="0"CELLSPACING="0"><TR><TDWIDTH="33%"ALIGN="left"VALIGN="top"><AHREF="itrafmon.html">&#60;&#60;&#60; Previous</A></TD><TDWIDTH="34%"ALIGN="center"VALIGN="top"><AHREF="manual.html">Home</A></TD><TDWIDTH="33%"ALIGN="right"VALIGN="top"><AHREF="x1047.html">Next &#62;&#62;&#62;</A></TD></TR><TR><TDWIDTH="33%"ALIGN="left"VALIGN="top">The IP Traffic Monitor</TD><TDWIDTH="34%"ALIGN="center"VALIGN="top"><AHREF="itrafmon.html">Up</A></TD><TDWIDTH="33%"ALIGN="right"VALIGN="top">Additional Information</TD></TR></TABLE></DIV></BODY></HTML>

⌨️ 快捷键说明

复制代码 Ctrl + C
搜索代码 Ctrl + F
全屏模式 F11
切换主题 Ctrl + Shift + D
显示快捷键 ?
增大字号 Ctrl + =
减小字号 Ctrl + -