Regarding stat report from OpenDPI

9 views
Skip to first unread message

codingfreak

unread,
Oct 22, 2009, 12:45:36 AM10/22/09
to opendpi
Hi

I have a small doubt regarding the final stat report published by
OpenDPI.

I do see some packets missing in the numbers ... correct if I am wrong
on this issue

pcap file contains
ip packets: 289 of 500 packets total
ip bytes: 59747
unique ids: 13
unique flows: 10

detected protocols:
unknown packets: 245 bytes: 55548
flows: 5
NETBIOS packets: 44 bytes: 4199
flows: 5

Total packets captured are 500 ... but detected protocols just show
the sum of ip-packets i.e. 289. What about the remaining 211
packets .... no info about them ??

--
Thanks & Regards

www.codingfreak.blogspot.com

Joel Ebrahimi

unread,
Oct 22, 2009, 12:55:07 AM10/22/09
to ope...@googlegroups.com
Non ip packets probably? 

If its a pcap look at it in wireshark.

codingfreak

unread,
Oct 22, 2009, 1:16:12 AM10/22/09
to opendpi
Sorry I am new to DPI stuff ... my question might be naive. So the
remaining protocols other than of IP are not of much use for DPI hence
they are simply discarded ...

--
Thanks & Regards

www.codingfreak.blogspot.com

On Oct 22, 9:55 am, Joel Ebrahimi <joel.ebrah...@gmail.com> wrote:
> Non ip packets probably?
> If its a pcap look at it in wireshark.
>

Maximilian Burkhardt

unread,
Nov 3, 2009, 2:03:55 PM11/3/09
to opendpi
Many packets sent through the network are internal only and not
related to the internet-- ARP packets are the most common. This type
of data is likely what is taking up about half of the packets your
captured.
Reply all
Reply to author
Forward
0 new messages