Tuesday, November 6, 2018

(Linux / Unix) Bi-Directional Flows Using IFtop and NetOptics Tap

Question:

When viewing IFtop on a network tap (in promiscuous mode) all traffic is shown across the interface as “received”; zero bytes are transmitted. Is there a way for the tapped interface (or mirrored port) to accurately display transmitted packets, rather than classify them all as packets “received”? For example, on a WAN tap, it would be helpful to have iftop interpret packets leaving the interface as “transmitted”.

Overview:

This is a NON-commercial “homelab” environment. All costs are borne by me, out of pocket.

Two configuration yield the same result:

Config 1

WAN => NetOptics TP-CU3-ZD-DC => ESXi 6.0u3 Host (vSwitch#1 + VMs)

Config 2

Juniper ex2200 mirrors Trunk => ESXi 6.0u3 Host (vSwitch#2 + VMs)

Please let me know if this is a limitation of the Linux network stack, or if it would be helpful to provide screenshots for iftop, ESXi vSwitch or anything else.

Thank you for you time.



No comments:

Post a Comment