IPTraf-ng User's Manual

This manual is released under the terms of the GNU Free Documentation License of March, 2000 as published by the Free Software Foundation, reproduced in this manual as Appendix B.

IPTraf-ng is open-source software released under the terms of the GNU General Public License version 2 or any later version as published by the Free Software Foundation, reproduced in the LICENSE file in the distribution's top-level directory.

The accomanying software and the information contained in this document are provided "AS IS" without warranty of any kind, express or implied, including, without limitation, the implied warranties of mercantability or fitness for any particular purpose.

In no event shall the author be liable for any indirect, special, consequential, or incidental damages arising from the use of this manual or the accompanying software even if the author has been advised of the possibility of such damages.

Linux is a registered trademark of Linus Torvalds. Pentium is a registered trademark of Intel Corporation. All other trademarks are property of their respective owners.

Some structure declarations were based on code copyrighted by the Regents of the University of California.


Table of Contents
About This Document
1. For Additional Information
2. Document Conventions
1. Getting Started
1.1. About IPTraf-ng
1.2. Installation
1.2.1. System Requirements
1.2.2. Availability
1.3. Starting and Stopping IPTraf-ng
1.4. Command-line Options
1.5. Using the Menus
1.6. Exiting IPTraf-ng
2. Preparing to Use IPTraf-ng
2.1. Number Display Notations
2.2. Instances and Logging
2.3. Screen Update Delays
2.4. Supported Network Interfaces
3. The IP Traffic Monitor
3.1. The Upper Window
3.1.1. Closed/Idle/Timed Out Connections
3.1.2. Sorting TCP Entries
3.2. Lower Window
3.2.1. Entry Details
3.3. Additional Information
4. Network Interface Statistics
4.1. General Interface Statistics
4.2. Detailed Interface Statistics
5. Statistical Breakdowns
5.1. Packet Sizes
5.2. TCP and UDP Traffic Statistics
5.2.1. Sorting TCP/UDP Entries
5.2.2. Additional Information
6. LAN Station Statistics
6.1. Sorting the LAN Station Monitor Entries
6.2. Additional Information
7. Filters
7.1. IP Filters
7.1.1. Defining a New Filter
7.1.2. Applying a Filter
7.1.3. Editing a Defined Filter
7.1.4. Deleting a Defined Filter
7.1.5. Detaching a Filter
7.2. ARP, RARP, and other Non-IP Packet Filters
8. Configuring IPTraf-ng
8.1. Toggles
8.1.1. Reverse DNS Lookups
8.1.2. TCP/UDP Service Names
8.1.3. Force promiscuous
8.1.4. Color
8.1.5. Logging
8.1.6. Activity mode
8.1.7. Source MAC addrs in traffic monitor
8.2. Timers
8.2.1. TCP Timeout
8.2.2. Log Interval
8.2.3. Screen Update Interval
8.2.4. TCP closed/idle persistence
8.3. Custom Information
8.3.1. Additional ports
8.3.2. Delete port/range
8.3.3. LAN Station Identifiers
9. Background Operation
A. Messages
A.1. IPTraf-ng Messages
A.2. Resolving Process Messages
B. GNU Free Documentation License
B.1. PREAMBLE
B.2. APPLICABILITY AND DEFINITIONS
B.3. VERBATIM COPYING
B.4. COPYING IN QUANTITY
B.5. MODIFICATIONS
B.6. COMBINING DOCUMENTS
B.7. COLLECTIONS OF DOCUMENTS
B.8. AGGREGATION WITH INDEPENDENT WORKS
B.9. TRANSLATION
B.10. TERMINATION
B.11. FUTURE REVISIONS OF THIS LICENSE
B.12. How to use this License for your documents
List of Tables
2-1. Numeric Display Notations
List of Figures
1-1. The IPTraf-ng Main Menu
2-1. The logfile prompt dialog
3-1. The IP traffic monitor
3-2. The IP traffic monitor sort criteria
4-1. The general interface statistics screen
4-2. The detailed interface statistics screen
5-1. The packet size statistical breakdown
5-2. The TCP/UDP service monitor
5-3. The TCP/UDP monitor's sort criteria
6-1. The LAN station monitor
6-2. The LAN station monitor's sort criteria
7-1. The Filters submenu
7-2. The IP filter menu
7-3. The IP filter name dialog
7-4. The filter rule selection screen. Selecting an entry displays that set for editing
7-5. The IP filter parameters dialog
8-1. The IPTraf-ng configuration menu
8-2. The Timers configuration submenu