[H-GEN] IP Traffic Monitoring

Russell Stuart rstuart at lubemobile.com.au
Tue Sep 9 19:34:29 EDT 2003


[ Humbug *General* list - semi-serious discussions about Humbug and     ]
[ Unix-related topics. Posts from non-subscribed addresses will vanish. ]

I need some pointers for debugging an ISDN link.  The link is currently
overloaded, and I want to know why.

The General Interface Statistics screen of iptraf says that approx 50%
of the traffic falls under the "BadIp" heading, which the manual says
are IP packets with checksum errors.  An "ip -statistics link" says
there are no errors, but I suspect that mean link layer errors, not
layer 3/4 errors.  Is there some other way to confirm there are IP
checksum errors?

Given that there are, is there some way to see the contents of those
packets?  Not unsurprisingly, they don't seem to get to tcpdump.  I
would like to know where they are coming from.  They don't seem to be
coming from the sources I expect, as quick check shows the links from
those sources have bad latency, as you would expect from an overloaded
link, but no dropped packets.

--
* This is list (humbug) general handled by majordomo at lists.humbug.org.au .
* Postings to this list are only accepted from subscribed addresses of
* lists 'general' or 'general-post'.  See http://www.humbug.org.au/



More information about the General mailing list