Quoting Paolo Lucente <[EMAIL PROTECTED]>:

Hi again,

> OK. Did you already try with a 3rd-party application using libpcap
> API, just to have a clue of where the problem lies?

I just installed Darkstat, which is based on libpcap as well to verify  
the results. The traffic reported by Darkstat is much more sane.  
Unfortunately it isn't easy to compare traffic reported by Darkstat to  
the traffic reports of my ISP, so I can't say for certain that the  
traffic reported is correct. However, Darkstat reports that most of  
the traffic going through is ESP since the hosts behind the gateway  
offer VPN services. Some DNS, ISAKMP and NTP traffic is reported as  
well so I guess it might be rather accurate.

> Stupid question, i know: does your gateway give any service to your  
> internal hosts that could explain such difference?

Nope. It does firewalling and should be doing accounting and that's it.

> Do you have just a single big bytes counter back from your provider?
> If not, can you reckon any pattern that might be useful for  
> investigating what's happening?

Yes, unfortunately. My ISP offers counters for total incoming and  
outgoing traffic for a certain timeframe and that's it.

Thanks
-- 
Daniel Bramkamp


_______________________________________________
pmacct-discussion mailing list
http://www.pmacct.net/#mailinglists

Reply via email to