Re: Comparing an old flow snapshot with some packet size data

"Dorian R. Kim" <dorian@cic.net> Fri, 09 August 1996 02:15 UTC

Received: from ietf.org by ietf.org id aa25622; 8 Aug 96 22:15 EDT
Received: from cnri by ietf.org id aa25618; 8 Aug 96 22:15 EDT
Received: from murtoa.cs.mu.OZ.AU by CNRI.Reston.VA.US id aa18454; 8 Aug 96 22:14 EDT
Received: from mailing-list by murtoa.cs.mu.OZ.AU (8.6.9/1.0) id LAA13843; Fri, 9 Aug 1996 11:56:41 +1000
Received: from munnari.OZ.AU by murtoa.cs.mu.OZ.AU (8.6.9/1.0) with SMTP id LAA13814; Fri, 9 Aug 1996 11:44:55 +1000
Received: from nic.hq.cic.net by munnari.OZ.AU with SMTP (5.83--+1.3.1+0.56) id BA07002; Fri, 9 Aug 1996 11:44:50 +1000 (from dorian@cic.net)
Received: from nic.hq.cic.net (nic.hq.cic.net [198.87.19.2]) by nic.hq.cic.net (8.7.5/CICNet) with SMTP id VAA04609; Thu, 8 Aug 1996 21:44:41 -0400 (EDT)
Date: Thu, 08 Aug 1996 21:44:40 -0400
Sender: ietf-archive-request@ietf.org
From: "Dorian R. Kim" <dorian@cic.net>
X-Orig-Sender: dorian@cic.net
Reply-To: "Dorian R. Kim" <dorian@cic.net>
To: "Kent W. England" <kwe@6sigmanets.com>
Cc: big-internet@munnari.oz.au
Subject: Re: Comparing an old flow snapshot with some packet size data
In-Reply-To: <2.2.32.19960806000836.00d194b8@mail.cts.com>
Message-Id: <Pine.SOL.3.95.960808213714.4046F-100000@nic.hq.cic.net>
Mime-Version: 1.0
Content-Type: TEXT/PLAIN; charset="US-ASCII"
Precedence: bulk

Darren Kerr of Cisco pointed out the fact that flows are not bi-directional,
i.e. a TCP session is two flows, and that meaningful FTP data is FTPD, which
stand for FTP Data, so it throws off some of the hypotheses discussed here.

Some more itsy bitsy data until I have real stuff to play with:

This is from a customer aggregation box.

dgd#sh ip ca flow
IP packet size distribution (3992M total packets):
   1-32   64   96  128  160  192  224  256  288  320  352  384  416  448  480
   .005 .489 .058 .016 .013 .008 .009 .012 .011 .015 .004 .005 .002 .002 .002

    512  544  576 1024 1536 2048 2560 3072 3584 4096 4608
   .005 .003 .142 .000 .114 .075 .000 .000 .000 .000 .000

IP Flow Switching Cache, 10539 active, 54997 inactive, 257164236 added
  0 flows exported, 0 not exported, 0 export msgs sent
  3 cur max hash, 257 worst max hash, 11801 valid buckets
  0 flow alloc failures
  statistics cleared 1423044 seconds ago

Protocol         Total  Flows   Packets Bytes  Packets Active(Sec) Idle(Sec)
--------         Flows   /Sec     /Flow  /Pkt     /Sec     /Flow     /Flow
TCP-Telnet     1566034    1.1       129    70    142.2     115.3      44.4
TCP-FTP        5836648    4.1         6    91     26.3      12.4      45.7
TCP-FTPD       3560889    2.5        86   464    216.5      49.2      45.7
TCP-WWW      139280025   97.8        11   319   1137.3       8.2      45.9
TCP-SMTP      22840124   16.0        10   160    166.6       9.8      45.9
TCP-X            58694    0.0       127   176      5.2     106.0      44.3
TCP-BGP        1339769    0.9         2    50      2.6       9.2      44.5
TCP-Frag        123389    0.0         9   306      0.7      17.6      45.3
TCP-other     20351999   14.3        70   354   1008.7      61.2      45.2
UDP-DNS       39827050   27.9         3   103     96.7       6.7      45.8
UDP-NTP        5321916    3.7         2    76      7.6       0.8      45.9
UDP-TFTP           106    0.0         4    94      0.0      22.2      44.2
UDP-Frag          1829    0.0        59   296      0.0      69.3      45.1
UDP-other      7809191    5.4        19   142    108.4      27.6      45.3
ICMP           9140968    6.4         3   154     24.5       7.7      45.8
IGMP             39621    0.0        37   422      1.0      44.5      44.9
IPINIP           44911    0.0       626   282     19.7     104.2      43.7
GRE              12545    0.0      2233   272     19.6     208.4      42.6
IP-other           587    0.0        34   525      0.0      18.2      46.2
Total:       257156295  180.7        16   302   2984.5      14.1      45.8


-dorian