Re: Network Traffic?

Jan Engvald LDC (Jan.Engvald@LDC.lu.se)
Wed, 07 Jun 1995 12:46:30 +0200


>This isn't directly related to CU-SeeMe, but I'm wondering if anyone has any
>resources for network traffic analysis. I'm interested in overall stuff, and
>by how much is in use by CU-SeeMe and similar apps. Anyone have any map /
>number locations?

Appended is some statistics collected for the UNINETT traffic into and out
from Norway. I have no reason to belive the other Nordic countries would
differ significantly.


Jan Engvald, Lund University Computing Center
________________________________________________________________________
Address: Box 783 E-mail: Jan.Engvald@ldc.lu.se
S-220 07 LUND Earn/Bitnet: XJELDC@SELUND
SWEDEN VAXPSI: psi%2403732202020::xjeldc
Office: Soelvegatan 18 X.400: S=Engvald/G=Jan/O=ldc/
Telephone: +46 46 2227458 PRMD=lu/ADMD=sunet/C=se
Telefax: +46 46 138225 WWW: http://www.lu.se/

8888888888888888888888888888888888888888888888888888888888888888888888888888

Date: Thu, 11 May 1995 15:53:33 +0200
From: Havard Eidnes <Havard.Eidnes@runit.sintef.no>
Subject: RE: traffic distribution (was: bottleneck in sprint's network?)

> It would also be nice to have some protocol distribution or
> traffic source statistics but I understand it's bit hard or
> nearly impossible to implement with current configuration and
> traffic levels.

Well, I have done a simple study for the traffic coming in to or
going out of Uninett towards NORDUnet. We still have a single
ethernet where this traffic passes (and yes, it's heavily
loaded). However, this permits us to fairly easily do some
traffic type measurements using NNStat on a separate machine.

The measurements for this data covers approximately the last week
of March and the first week of April, and the some of the results
for this period were:

<lots of detailed tables deleted>

The main picture is quite clear, the largest traffic sources in
our case were:

packets Bytes
www/http 29% 33%
ftp-data 18% 26%
CU-SeeMe 6% 11%
IP-multicast 6% 7%

for a total of 59% of all packets and 77% of all bytes.

In comparison, maybe somewhat surprising:

smtp 4% 2%
nntp 3% 3%

What is also clear is that traffic to "unregistered TCP ports" is
a significant portion in our case, much of this is MUD servers
and the like.

Hope this was something in the direction of what was desired.

- H=E5vard