Quoting Paolo Lucente <[EMAIL PROTECTED]>: Hi again,
> OK. Did you already try with a 3rd-party application using libpcap > API, just to have a clue of where the problem lies? I just installed Darkstat, which is based on libpcap as well to verify the results. The traffic reported by Darkstat is much more sane. Unfortunately it isn't easy to compare traffic reported by Darkstat to the traffic reports of my ISP, so I can't say for certain that the traffic reported is correct. However, Darkstat reports that most of the traffic going through is ESP since the hosts behind the gateway offer VPN services. Some DNS, ISAKMP and NTP traffic is reported as well so I guess it might be rather accurate. > Stupid question, i know: does your gateway give any service to your > internal hosts that could explain such difference? Nope. It does firewalling and should be doing accounting and that's it. > Do you have just a single big bytes counter back from your provider? > If not, can you reckon any pattern that might be useful for > investigating what's happening? Yes, unfortunately. My ISP offers counters for total incoming and outgoing traffic for a certain timeframe and that's it. Thanks -- Daniel Bramkamp _______________________________________________ pmacct-discussion mailing list http://www.pmacct.net/#mailinglists
