Odd new network traffic

Hello all,
2 NW 6 - 10.69.0.1 & 10.69.0.3
1 OES (NW) - 10.69.0.2
1 Windows 2000
1 Windows 2003
Yesterday my Netware & OES servers started broadcasting traffic on UDP port
427 to 10.0.0.34 port 1025. 10.0.0.34 is an invalid address. I can't find
any configuration changes that occurred before they started this
broadcasting. It's creating quite a bit of traffic and I would like to shut
it down.
SLP hasn't been configured on this network for 6 years and it has been
working fine. Does anyone have any idea what could be causing this?
Daniel Blake
Milford Central School

We thought so too. I was wondering if some sort of communication loop could
have been started and when the filter was put in place it broke the loop.
Here is another piece of the puzzle. When I pinged the 10.0.0.34 address
the reply I got was a NATED 192.168. address. I thought it was quite that
one private IP scheme was NATing to another private IP range. Then I
thought someone might have brought in a Linksys or D-link router to try and
get around our policies. A BoarderManager tech from BOCES told me he had
seen this kind of behavior from the firewall sometimes when it got
unexpected traffic.
I don't think it could be a rouge router seeing as the traffic didn't start
right back up when I removed the filter.
Daniel Blake
Milford Central School
>>> Edison Ortiz<[email protected]> 12/5/2006 4:51 PM >>>
On 12/5/2006 Daniel Blake wrote:
> I removed the
> filter after a few minutes and that traffic didn't show back up.
Interesting ....
Edison Ortiz
Novell Product Support Forum SysOp
(No Email Support, Thanks !)

Similar Messages

  • Is there anyway to monitor network traffic on the newer Time Capsules, similar to the SNMP monitoring previously?

    Is there anyway to monitor network traffic on the newer Time Capsules, similar to the SNMP monitoring previously?

    Can I use a real router and still have the Time Capsule for backups etc?
    Yes, that is what Bridge Mode is for.  Just connect the Time Capsule to a LAN <--> Ethernet port on your "main" router.

  • Thunderbolt to Firewire Adapter & New Network Interface Message

    I am using the new Thunderbolt to Firewire Adapter. Why is it that every time I use it, I get the following message:
    "A new network interface has been detected. The Thunderbolt FireWire Slot 2 network interface has not been set up. To set up this interface, use network preferences."
    All I want to do is mount external hard drives that don't have Thunderbolt ports to my iMac, via Thunderbolt because I am using the iMac's single Firewire port for something else. The drives do successfully mount, but why do I keep getting this message whenever I connect them again?

    I have no doubt what you say to do would get rid of the message for me. However, both myself and an Apple Store employee think it is odd that the message comes up in the first place. We're both curious about it, and he's going to look into it.
    We tested it on a computer at the store, and found that it happens on Lion too.

  • How do I time out my thread if there is no network traffic

    How do I time out my thread if there is no network traffic for a given time? I have the following code listening for data:
    StringBuffer requestLine = new StringBuffer();
    int c;
    while(true) {
        c = in.read();
        if(c == '\r' || c == '\n') {//Not sure here???
            break;
        requestLine.append((char)c);
    }But how do I time this out if there has been no traffic for lets say 5 minutes?

    Have you redefined 'in'?
    If it's a raw socket connection, you can use the Socket.setSoTimeout method before you open the connection to specify how long it should hold it open if there is no data available.

  • Unknown network traffic / router traffic monitoring

    So I got a new PC with windows 7 on it, and I installed this gadget that monitors network traffic, and it shows a lot of traffic that my local PC isn't showing, so I am thinking there is something running on the LAN that I can't see. I was looking to find a live, better program to monitor the actiontec router, for traffic. anyone know of anything that can maybe show me who is using all the bandwidth on my network?
    i have found software for Linksys, but nothing for the Actiontec.
    Thanks,
    Quasimodem
    Fios in Florida
    Solved!
    Go to Solution.

    Keep in mind that when looking at Wireshark (sniffer) software there are different types of traffic:
    Unicast
    Broadcast
    Multicast
    Unicast is traffic between two devices.  You will see the traffic between the PC with wireshark and another device on your local network such as a printer, another PC or the Router.  You should not see traffic between another PC and the Internet for example.  Using a phone as an example some calls you and the conversation is between you and the person on the other end of the phone.  This is unicast traffic.  Using defaults of the actiontec, IP address seen will be 192.168.1.1 for the router and 192.168.1.2-99 for devices on your network.  If you have the TV service, 192.168.1.100-1xx is used for the cable boxes.
    Broadcast traffic is traffic sent to all devices.  Its not directed toward a particular PC but rather usually looking for information.  In a sniffer trace you will see broadcast traffic. Going back to the phone example, someone makes an announcement on an overhead intercom system that is broadcast traffic.  Broadcast traffic will be seen as 192.168.255.255
    Multicast traffic is traffic from one device for many devices.  Usually used in video feeds.   Using the phone system as an example someone wishes to tell a group of people something so instead of calling each person up and telling them each person who wants the information joins a conference bridge.  Anyone is allowed to listen but only those that wish to get the information receive it.  Generally how multicast works.  Multicast traffic will be seen as IP address 224.x.x.x or something of the sorts where the address will be 2xx.x.x.x.  
    I hope this makes sense.  Probably more information than you needed but at least it will help you understand what wireshark is telling you.

  • Yahoo odd news video will not play,

    When I try to watch odd news video all I get is a blank screen with a revolving circle. Other videos are fine.

    Start Firefox in -> [[Safe Mode]] to check if your add-ons/extension are causing the problem.
    * Also see this article -> [[Troubleshooting extensions and themes]]
    Perform the suggestions mentioned in the following articles:
    * [https://support.mozilla.com/en-US/kb/Template:clearCookiesCache Clear Cookies & Cache]
    * [[How to clear the cache#w_clear-the-cache|Clear the Network Cache]]
    Check and tell if its working.
    You can also try to clear the Flash cookies.
    Flash Website Storage Settings panel:
    * http://www.macromedia.com/support/documentation/en/flashplayer/help/settings_manager07.html
    Global Storage Settings Panel:
    * http://www.macromedia.com/support/documentation/en/flashplayer/help/settings_manager03.html
    Flash Local storage settings Help:
    * http://www.macromedia.com/support/documentation/en/flashplayer/help/help02.html

  • Excess network traffic - what's causing it?

    I recently purchased a Mac Mini Server and today I reinstalled my server software to try to fix some permission problems.
    Anyway, I must have turned something on or off incorrectly because my network traffic suddenly started going through the roof for about six hours until the monthly cap with my ISP was exceeded and they slowed my connection.
    Any ideas what could be causing this excessive traffic?
    I am confident that it wasn't the result of any large downloads etc (18GB in 6 hrs!) and I can't help but feel it was just an incorrect setup somewhere.
    As you can probably tell, I'm all new to this server business so please excuse my naivety.
    A screen shot of my network activity graph is at http://idisk.mac.com/mtilley/Public/temp/Activity.png
    I turned the web service off before taking the screen shot but that was about 9:00 pm.

    That could well be it.
    Just checked the size of the downloads - 17.64 GB.
    Thanks cpragman for your much appreciated help.

  • GetURL generating "no network traffic"

    i don't have the code in front of me so can't quote from it
    i'm afraid, but as a general picture:
    we have a pop up browser window generated by the
    FCK editor within which 2
    iframes inside of which either <object> & <embed>
    tags or geoff sterns
    swfobject include
    (the result with either embed method is the same) and a swf. said
    swf then has this code:
    getURL( destination, "", "POST" );
    the problem is, i'm told by my java guys, this call is
    generating ZERO network traffic.
    any ideas why?

    never forget your window declaration. here we have before and
    after:
    getURL( destination, "", "POST" );
    getURL( destination, "_self", "POST" );
    the second one works. oddly, the first WAS working, firstly
    for years using a previous rich text editor and then even now with
    our latest rich text editor on our test environment, only not on
    our live environment. and the java guys are glad to see it working
    but still wonder quite what the problem is because as far as they
    can tell everything is similarly named on test as on live.
    i don't know, all i know is that using "_self" made a world
    of difference and i recommend it 100%. it's great!!! :)

  • Client/Server network traffic.

    I don't know if here is the right forum to ask it, but let's go on.
    Nowadays we a system on Forms 4.5/windows/Oracle 8.0
    We have some clients machines linked to the server by a Frame-Relay link and we use Windows 2000 Terminal Server to reduce the network traffic.
    Well, we are gonna update to Forms 6i/Oracle 8i.
    I would like to know if Forms Server can be a good option to Windows 2000 Terminal Server.
    If I haven't been clear with my question I'll can do it again. I'm new on Forms 6i and I've just installed it to test (It hasn't been working yet....)
    Thanks in advance
    Ronaldo.

    This could provoke quite a discussion.
    "If your client are on slow links you may, for example query 10,000 rows of data. "
    Generally, forms shouldn't be pulling back tens of thousands of rows from the database. Your user is unlikely to page through that much, so either you want a summary (which is best calculated on the database server and the summary results dragged across the network) or you are paging through records in the tens, not tens of thousands. (Look at the 'Number of recods buffered' property in your base table blocks. Bet it's one or two digits, not five!)
    "The information that is transmitted to the client is basically screen draw information - and this will be alot less than the 10,000 rows you were querying before. "
    As above. In client/server you shouldn't have been bringing stuff from the database down to the client that wasn't going to be on the screen anyway, especially if you had a slow network.
    Depending on how your application is written, it could well peform a lot worse on the web than in client server. Rather than having the client do a fair share of the work, it's now got to keep talking to the application server to get anything done.
    For example, because navigation triggers don't allow the use of restricted built-ins, rather than putting code in a 'post-text-item/when-validate-item' trigger on the relevant item, it gets put in a form level 'when-new-item-instance' trigger. It's a bit untidy in client/server but workable. Put it on the web, and every time the user tabs between fields, the form has to go off to the application server to fire the when-new-item-intance trigger to tell it what to do next.
    Another 'speed-bump' is if you have any synchronize bits (eg in a post-query trigger, or as part of a "I'm 10% complete" information messages in long running loops). These will also generate network traffic between the app server and form.
    While web server does have advantages, I wouldn't be selling it on it's performance improvements.

  • Slow network traffic when replica1 is started

    Hi, I have a problem with a WLSS cluster. Each time I started the replica the network traffic turns so slow. I dont know how to explain that. Besides I make a Camtasia video that you could download from this URL.
    http://rapidshare.com/files/174413972/BEA_ping.wmv.html
    I hope you can told me whats going on.
    Thanks a lot
    Greetings

    I've also noticed that my airport express is blinking green, showing network traffic, when both my imac and ipad are turned off - even though I have the airport express set to be hidden, password protected and limited to certain airport IDs.
    The cable company sends continuous, almost non-stop garbage down the line. The tech guy at the cable company would say that the devices are "associating". That's why you see the green light flashing. You might want to turn off the "flash on activity" option and simply have it glow solid green...unless you like to watch the flashing, or you want to switch to DSL.
    Try turning off the anti-virus to see if that helps wireless perform better. Most anti-virus applications do more harm than good. Otherwise, look for wireless interference from another nearby wireless network, cordless phone, or even that new security system at the neighbors.

  • Network Traffic Part 2

    Hi Joe,
    I am monitorring again the network traffic output of my rhel4 server, using the script you gave me,
    and I got the following:
    11/04/10 00:00:07,RXbytes:761952,TXbytes:427484
    11/04/10 01:00:07,RXbytes:1253865,TXbytes:903771
    11/04/10 02:00:07,RXbytes:561288,TXbytes:126774
    11/04/10 03:00:08,RXbytes:614364,TXbytes:327579
    11/04/10 04:00:08,RXbytes:626030,TXbytes:581122
    11/04/10 05:00:08,RXbytes:448505,TXbytes:3935
    11/04/10 06:00:07,RXbytes:363288,TXbytes:256
    11/04/10 07:00:08,RXbytes:418344,TXbytes:512
    11/04/10 08:00:07,RXbytes:3075147,TXbytes:20871024
    11/04/10 09:00:08,RXbytes:21268121,TXbytes:96990878
    11/04/10 10:00:07,RXbytes:28459877,TXbytes:311859635
    11/04/10 11:00:08,RXbytes:7230007,TXbytes:37973840
    11/04/10 12:00:08,RXbytes:6117714,TXbytes:41316205
    11/04/10 13:00:08,RXbytes:9299506,TXbytes:59563899
    11/04/10 14:00:07,RXbytes:12474670,TXbytes:46555827
    11/04/10 15:00:08,RXbytes:12471005,TXbytes:129434535
    11/04/10 16:00:08,RXbytes:7906737,TXbytes:64104023
    11/04/10 17:00:08,RXbytes:29303369,TXbytes:145990135
    11/04/10 18:00:08,RXbytes:14466168,TXbytes:44081112
    11/04/10 19:00:07,RXbytes:16192064,TXbytes:52467858
    11/04/10 20:00:08,RXbytes:1668065122,TXbytes:1358371970
    11/04/10 21:00:08,RXbytes:1232966,TXbytes:685626
    11/04/10 22:00:07,RXbytes:982910,TXbytes:477852
    11/04/10 23:00:07,RXbytes:761526,TXbytes:218669
    11/05/10 00:00:07,RXbytes:809886,TXbytes:982614
    11/05/10 01:00:08,RXbytes:642301,TXbytes:126982
    11/05/10 02:00:07,RXbytes:635841,TXbytes:218607
    11/05/10 03:00:07,RXbytes:740963,TXbytes:1008036
    11/05/10 04:00:07,RXbytes:624231,TXbytes:394317
    11/05/10 05:00:08,RXbytes:448494,TXbytes:3653
    11/05/10 06:00:08,RXbytes:415485,TXbytes:640
    11/05/10 07:00:07,RXbytes:389860,TXbytes:512
    11/05/10 08:00:07,RXbytes:26640050,TXbytes:353528988
    11/05/10 09:00:07,RXbytes:17023417,TXbytes:209170566
    11/05/10 10:00:07,RXbytes:48096899,TXbytes:592254609
    11/05/10 11:00:07,RXbytes:29606627,TXbytes:-4094024665
    11/05/10 12:00:07,RXbytes:14057405,TXbytes:94579667
    11/05/10 13:00:07,RXbytes:11446821,TXbytes:42764768I still got negative at 11am todate, I know I didnot edit the program ne more :(
    Don;t you think it is the peak ( highest period)?
    Thanks a lot

    Hi Dude :)
    I did not know the "sar" has also network traffic monitoring, until you gave me the docs link which is:
    http://www.linux-tutorial.info/modules.php?name=News&file=article&sid=3230
    I got this network traffic statistics from the "sar" default monitoring system.
    23:00:01        IFACE   rxpck/s   txpck/s   rxbyt/s   txbyt/s   rxcmp/s   txcmp/s  rxmcst/s
    23:10:01           lo     68.40     68.40  14143.49  14143.49      0.00      0.00      0.00
    23:10:01         eth0      3.86      1.90    528.59    363.05      0.00      0.00      0.00
    23:10:01         eth1      0.27      0.03     22.40      2.09      0.00      0.00      0.00
    23:10:01         eth2      0.25      0.00     21.17      0.39      0.00      0.00      0.00
    23:10:01         sit0      0.00      0.00      0.00      0.00      0.00      0.00      0.00
    23:20:01           lo     62.71     62.71  11910.61  11910.61      0.00      0.00      0.00
    23:20:01         eth0      2.70      0.64    292.53    134.17      0.00      0.00      0.00
    23:20:01         eth1      0.27      0.03     22.85      2.00      0.00      0.00      0.00
    23:20:01         eth2      0.25      0.00     21.30      0.39      0.00      0.00      0.00
    23:20:01         sit0      0.00      0.00      0.00      0.00      0.00      0.00      0.00
    23:30:01           lo     66.57     66.57  13785.36  13785.36      0.00      0.00      0.00
    23:30:01         eth0      1.97      0.24    168.32     35.51      0.00      0.00      0.00
    23:30:01         eth1      0.50      0.06     36.43      3.99      0.00      0.00      0.00
    23:30:01         eth2      0.43      0.00     32.03      0.39      0.00      0.00      0.00
    23:30:01         sit0      0.00      0.00      0.00      0.00      0.00      0.00      0.00
    23:40:01           lo     67.49     67.49  14342.50  14342.50      0.00      0.00      0.00
    23:40:01         eth0      1.81      0.24    155.01     35.56      0.00      0.00      0.00
    23:40:01         eth1      0.26      0.02     21.75      1.49      0.00      0.00      0.00
    23:40:01         eth2      0.23      0.00     20.00      0.39      0.00      0.00      0.00
    23:40:01         sit0      0.00      0.00      0.00      0.00      0.00      0.00      0.00
    23:50:01           lo     68.37     68.37  13966.97  13966.97      0.00      0.00      0.00
    23:50:01         eth0      1.73      0.24    161.67     35.50      0.00      0.00      0.00
    23:50:01         eth1      0.38      0.03     29.16      1.99      0.00      0.00      0.00
    23:50:01         eth2      0.34      0.00     26.79      0.39      0.00      0.00      0.00
    23:50:01         sit0      0.00      0.00      0.00      0.00      0.00      0.00      0.00
    Average:           lo    147.36    147.36  13546.40  13546.40      0.00      0.00      0.00
    Average:         eth0     15.85     14.84   1627.46  10663.56      0.00      0.00      0.00
    Average:         eth1      1.73      1.65    144.72   1133.77      0.00      0.00      0.00
    Average:         eth2      0.32      0.00     25.54      0.39      0.00      0.00      0.00
    Average:         sit0      0.00      0.00      0.00      0.00      0.00      0.00      0.00Do you think its the similar with the eh0stat.sh you gave me? do you think I have to use this one instead? or do you think this one is more accurate? :)
    What does "lo" mean?
    23:00:01        IFACE   rxpck/s   txpck/s   rxbyt/s   txbyt/s   rxcmp/s   txcmp/s  rxmcst/s
    Average:           lo    147.36    147.36  13546.40  13546.40      0.00      0.00      0.00Thanks

  • 24 Hr Network Traffic Monitoring

    Hi Markus,
    I got this 24-hour Network traffic monitoring output using the program you gave me ;)
    I run every hour this > ./network-traffic.sh -c 1
    It will give me 1 line output like this,
    Monitoring eth0 every 3 seconds. (RXbyte total = 1 Gb TXbytes total = 2 Gb)
    RXbytes = 58 Kb TXbytes = 51 Kband I call this program every hour via cron, to produce and output like this:
    27-Oct-2010 00:00:07    RXbytes = 10 Kb TXbytes = 9 Kb
    27-Oct-2010 01:00:07    RXbytes = 11 Kb TXbytes = 9 Kb
    27-Oct-2010 02:00:07    RXbytes = 7 Kb TXbytes = 6 Kb
    27-Oct-2010 03:00:07    RXbytes = 48 Kb TXbytes = 42 Kb
    27-Oct-2010 04:00:07    RXbytes = 448 b TXbytes = 0 b
    27-Oct-2010 05:00:08    RXbytes = 128 b TXbytes = 0 b
    27-Oct-2010 06:00:07    RXbytes = 128 b TXbytes = 0 b
    27-Oct-2010 07:00:08    RXbytes = 256 b TXbytes = 0 b
    27-Oct-2010 08:00:08    RXbytes = 14 Kb TXbytes = 24 Kb
    27-Oct-2010 09:00:07    RXbytes = 11 Kb TXbytes = 10 Kb
    27-Oct-2010 10:00:08    RXbytes = 11 Kb TXbytes = 10 Kb
    27-Oct-2010 11:00:07    RXbytes = 48 Kb TXbytes = 85 Kb
    27-Oct-2010 12:00:08    RXbytes = 9 Kb TXbytes = 8 Kb
    27-Oct-2010 13:00:07    RXbytes = 13 Kb TXbytes = 28 Kb
    27-Oct-2010 14:00:08    RXbytes = 53 Kb TXbytes = 46 Kb
    27-Oct-2010 15:00:08    RXbytes = 13 Kb TXbytes = 20 Kb
    27-Oct-2010 16:00:08    RXbytes = 13 Kb TXbytes = 20 Kb
    27-Oct-2010 17:00:08    RXbytes = 40 Kb TXbytes = 94 Kb
    27-Oct-2010 18:00:07    RXbytes = 13 Kb TXbytes = 30 Kb
    27-Oct-2010 19:00:08    RXbytes = 6 Kb TXbytes = 9 Kb
    27-Oct-2010 20:00:08    RXbytes = 12 Kb TXbytes = 12 Kb
    27-Oct-2010 21:00:08    RXbytes = 15 Kb TXbytes = 40 Kb
    27-Oct-2010 22:00:07    RXbytes = 9 Kb TXbytes = 11 Kb
    27-Oct-2010 23:00:07    RXbytes = 11 Kb TXbytes = 9 KbIs this output data gathering style valid?
    I want to give this report to my boss using spreadsheets, but I want to put comments like :
    1. at what hour is the network busiest?
    2. at what hour is the network the not-busiest?
    How do I sort this output from busiest (descending order)?
    Thanks a lot,
    Ms K

    Hi again markie,
    This is my actual source code of eth0stat.sh:
    # File: eth0stat.sh
    # Purpose: Gather network traffic increase between readings
    # Command: . ./eth0stat.sh
    ifcmd='/sbin/ifconfig eth0'
    timestamp=$(date "+%D %T")
    logfile=/u01/Monitor/eth0stat.txt
    old_rxbytes=$RXBYTES
    old_txbytes=$TXBYTES
    get_rxbytes() {
       $ifcmd | grep "RX bytes" | cut -d: -f2 | awk '{ print $1 }'
    get_txbytes() {
       $ifcmd | grep "TX bytes" | cut -d: -f3 | awk '{ print $1 }'
    RXBYTES=$(get_rxbytes); export RXBYTES
    TXBYTES=$(get_txbytes); export TXBYTES
    if [ $old_rxbytes > 0 ]; then
       diff_rxbytes=$(($RXBYTES - $old_rxbytes))
    else
       diff_rxbytes=0
    fi
    if [ $old_txbytes > 0 ]; then
       diff_txbytes=$(($TXBYTES - $old_txbytes))
    else
       diff_txbytes=0
    fi
    echo "$timestamp,RXbytes:$diff_rxbytes,TXbytes:$diff_txbytes" >> $logfileI created the new program you gave me (eth0stat.sh) and called it from cron every our, but I got this result:
    11/01/10 15:00:07,RXbytes:0,TXbytes:0
    11/01/10 16:00:07,RXbytes:0,TXbytes:0
    11/01/10 17:00:07,RXbytes:0,TXbytes:0
    11/01/10 18:00:07,RXbytes:0,TXbytes:0
    11/01/10 19:00:07,RXbytes:0,TXbytes:0
    11/01/10 20:00:07,RXbytes:0,TXbytes:0
    11/01/10 21:00:07,RXbytes:0,TXbytes:0
    11/01/10 22:00:08,RXbytes:0,TXbytes:0
    11/01/10 23:00:07,RXbytes:0,TXbytes:0
    11/02/10 00:00:07,RXbytes:0,TXbytes:0
    11/02/10 01:00:08,RXbytes:0,TXbytes:0
    11/02/10 02:00:08,RXbytes:0,TXbytes:0
    11/02/10 03:00:07,RXbytes:0,TXbytes:0
    11/02/10 04:00:07,RXbytes:0,TXbytes:0
    11/02/10 05:00:07,RXbytes:0,TXbytes:0
    11/02/10 06:00:08,RXbytes:0,TXbytes:0
    11/02/10 07:00:08,RXbytes:0,TXbytes:0
    11/02/10 08:00:07,RXbytes:0,TXbytes:0
    11/02/10 09:00:08,RXbytes:0,TXbytes:0
    11/02/10 10:00:08,RXbytes:0,TXbytes:0The output has all 0 bytes :( . Is there something I missed out?
    I compared it to the other one I got:
    1-Nov-2010 15:00:07     RXbytes = 10 Kb TXbytes = 9 Kb
    1-Nov-2010 16:00:07     RXbytes = 10 Kb TXbytes = 9 Kb
    1-Nov-2010 17:00:07     RXbytes = 10 Kb TXbytes = 9 Kb
    1-Nov-2010 18:00:07     RXbytes = 10 Kb TXbytes = 9 Kb
    1-Nov-2010 19:00:07     RXbytes = 10 Kb TXbytes = 9 Kb
    1-Nov-2010 20:00:07     RXbytes = 10 Kb TXbytes = 9 Kb
    1-Nov-2010 21:00:07     RXbytes = 10 Kb TXbytes = 9 Kb
    1-Nov-2010 22:00:08     RXbytes = 10 Kb TXbytes = 9 Kb
    1-Nov-2010 23:00:07     RXbytes = 11 Kb TXbytes = 9 Kb
    2-Nov-2010 00:00:07     RXbytes = 10 Kb TXbytes = 9 Kb
    2-Nov-2010 01:00:08     RXbytes = 10 Kb TXbytes = 9 Kb
    2-Nov-2010 02:00:08     RXbytes = 10 Kb TXbytes = 9 Kb
    2-Nov-2010 03:00:07     RXbytes = 7 Kb TXbytes = 6 Kb
    2-Nov-2010 04:00:07     RXbytes = 256 b TXbytes = 0 b
    2-Nov-2010 05:00:07     RXbytes = 320 b TXbytes = 0 b
    2-Nov-2010 06:00:08     RXbytes = 0 b TXbytes = 0 b
    2-Nov-2010 07:00:08     RXbytes = 466 b TXbytes = 0 b
    2-Nov-2010 08:00:07     RXbytes = 1 Mb TXbytes = 19 Mb
    2-Nov-2010 09:00:08     RXbytes = 1 Mb TXbytes = 22 Mb
    2-Nov-2010 10:00:08     RXbytes = 12 Kb TXbytes = 91 KbThe is seem to be movement starting at 8am Nov 2, 2010.
    Please help me debug the eth0stat.sh.
    Thanks again so much

  • Oracle oleDB generates lots of network traffic than Microsoft Oledb

    Hi,
    When calling the same stored proc. that returns a ref cursor, Oracle Oledb (1.34 MB) generates alot of network traffic than Microsoft Oledb (0.06 MB). The statistic is gathered using Windows 2000 Network Monitoring tools.
    Calling the same stored proc. that returns a ref cursor
    Oracle OleDB Microsoft Oledb
    Byte Received: 1408026 (1.34 M) 71032 (0.06 M)
    Byte Sent: 306468 (0.29M) 69914 ( 0.067M)
    Frame: 1263 414
    Network Utilization: 6%-14% 1%-3%
    Anyone know why is this case?
    Joe

    When working with ADO and VB6, I looked at the database server with SQL Trace and found that each dynamic SQL statement was parsed twice per execution. REF CURSORs certainly require several network round-trips in order to retrieve schema information for the dataset to be created. This behaviour probably increases network load.
    Unfortunately, I have not found any description of Oracle's OLEDB implementation. Hopefully, things will get better with the new, native OleDb data adapter.
    /Armin
    Previous post:
    multiple parsing of SELECTs O/S : N/A POST: REPLY (W/QUOTE)
    Author : Armin Type : N/A
    Date : Apr 7, 2001 12:51 PT
    System: OLEDB provider 8.1.7, server 8.1.7.
    Our VB code dynamically assembles SELECT statements and fetches recordsets with ADO function Recordset::Open. SQL TRACE shows that those SELECTs are parsed twice per execution. SELECTs embedded in stored procedures are parsed only once during the SP's life time (but then the stored procedure call itself is parsed once per execution).
    Parsing twice per execution consumes a lot of CPU. REF Cursors might reduce parsing but cause additional network roundtrips.
    How could I reduce the parse count?

  • Slow Airport Express blinking green - network traffic when all devices off?

    My G5 imac and airport express are lightning fast when everything boots up, slow as molasses later. The airport express is 3 feet away from my G5, and hooked up by ethernet to a cable modem.
    I've also noticed that my airport express is blinking green, showing network traffic, when both my imac and ipad are turned off - even though I have the airport express set to be hidden, password protected and limited to certain airport IDs. Is it possible that my airport are being hijacked, or is there another reason for the variability in speed? My MacScan and iAntiVirus report no malware or cookies or viruses.
    imac intel Mac OS X (10.6.4) airport express 5.5.1

    I've also noticed that my airport express is blinking green, showing network traffic, when both my imac and ipad are turned off - even though I have the airport express set to be hidden, password protected and limited to certain airport IDs.
    The cable company sends continuous, almost non-stop garbage down the line. The tech guy at the cable company would say that the devices are "associating". That's why you see the green light flashing. You might want to turn off the "flash on activity" option and simply have it glow solid green...unless you like to watch the flashing, or you want to switch to DSL.
    Try turning off the anti-virus to see if that helps wireless perform better. Most anti-virus applications do more harm than good. Otherwise, look for wireless interference from another nearby wireless network, cordless phone, or even that new security system at the neighbors.

  • L2L VPN issues with new network

    I've added a new network for a customer's firewall and I'm trying to get that network across the existing VPN tunnel to their DR site. The new network is 10.133.133.0/24 and I'm trying to get it to connect to 10.1.14.0/24 on the other side of the tunnel.
    I'm missing something, though, because when I do a packet-tracer to simulate traffic, it dies before getting encrypted. The output is below.
    What am I missing to get this traffic to even attempt to go across the tunnel?
    4344-FWL001#packet-tracer input backup icmp 10.133.133.10 0 0 10.1.14.20
    Phase: 1
    Type: ROUTE-LOOKUP
    Subtype: input
    Result: ALLOW
    Config:
    Additional Information:
    in   0.0.0.0         0.0.0.0         outside
    Phase: 2
    Type: ACCESS-LIST
    Subtype: log
    Result: ALLOW
    Config:
    access-group backup_acl in interface backup
    access-list backup_acl extended permit ip 10.133.133.0 255.255.255.0 10.1.14.0 255.255.255.0
    Additional Information:
    Phase: 3
    Type: CONN-SETTINGS
    Subtype:
    Result: ALLOW
    Config:
    class-map class-default
    match any
    policy-map global_policy
    class class-default
      set connection decrement-ttl
    service-policy global_policy global
    Additional Information:
    Phase: 4
    Type: IP-OPTIONS
    Subtype:
    Result: ALLOW
    Config:
    Additional Information:
    Phase: 5
    Type: INSPECT
    Subtype: np-inspect
    Result: ALLOW
    Config:
    Additional Information:
    Phase: 6
    Type: NAT-EXEMPT
    Subtype:
    Result: ALLOW
    Config:
      match ip backup 10.133.133.0 255.255.255.0 outside 10.1.14.0 255.255.255.0
        NAT exempt
        translate_hits = 40, untranslate_hits = 0
    Additional Information:
    Phase: 7
    Type: NAT
    Subtype:
    Result: ALLOW
    Config:
    nat (backup) 1 0.0.0.0 0.0.0.0
      match ip backup any outside any
        dynamic translation to pool 1 (216.211.133.59 [Interface PAT])
        translate_hits = 254, untranslate_hits = 18
    Additional Information:
    Phase: 8
    Type: NAT
    Subtype: host-limits
    Result: ALLOW
    Config:
    nat (backup) 1 0.0.0.0 0.0.0.0
      match ip backup any outside any
        dynamic translation to pool 1 (216.211.133.59 [Interface PAT])
        translate_hits = 254, untranslate_hits = 18
    Additional Information:
    Phase: 9
    Type: VPN
    Subtype: encrypt
    Result: DROP
    Config:
    Additional Information:
    Result:
    input-interface: backup
    input-status: up
    input-line-status: up
    output-interface: outside
    output-status: up
    output-line-status: up
    Action: drop
    Drop-reason: (acl-drop) Flow is denied by configured rule

    And what I get from isakmp debug:
    Feb 28 13:41:26 [IKEv1]: Group = 216.203.46.252, IP = 216.203.46.252, QM FSM error (P2 struct &0xc9f39e68, mess id 0xe0ba04c)!
    Feb 28 13:41:26 [IKEv1 DEBUG]: Group = 216.203.46.252, IP = 216.203.46.252, IKE QM Initiator FSM error history (struct &0xc9f39e68)  , :  QM_DONE, EV_ERROR-->QM_WAIT_MSG2, EV_TIMEOUT-->QM_WAIT_MSG2, NullEvent-->QM_SND_MSG1, EV_SND_MSG-->QM_SND_MSG1, EV_START_TMR-->QM_SND_MSG1, EV_RESEND_MSG-->QM_WAIT_MSG2, EV_TIMEOUT-->QM_WAIT_MSG2, NullEvent
    Feb 28 13:41:26 [IKEv1 DEBUG]: Group = 216.203.46.252, IP = 216.203.46.252, sending delete/delete with reason message
    Feb 28 13:41:26 [IKEv1 DEBUG]: Group = 216.203.46.252, IP = 216.203.46.252, constructing blank hash payload
    Feb 28 13:41:26 [IKEv1 DEBUG]: Group = 216.203.46.252, IP = 216.203.46.252, constructing IPSec delete payload
    Feb 28 13:41:26 [IKEv1 DEBUG]: Group = 216.203.46.252, IP = 216.203.46.252, constructing qm hash payload
    Feb 28 13:41:26 [IKEv1]: IP = 216.203.46.252, IKE_DECODE SENDING Message (msgid=216bc3cb) with payloads : HDR + HASH (8) + DELETE (12) + NONE (0) total length : 68
    Feb 28 13:41:26 [IKEv1 DEBUG]: Group = 216.203.46.252, IP = 216.203.46.252, IKE Deleting SA: Remote Proxy 10.1.14.0, Local Proxy 10.133.133.0
    Feb 28 13:41:26 [IKEv1]: Group = 216.203.46.252, IP = 216.203.46.252, Removing peer from correlator table failed, no match!
    Feb 28 13:41:26 [IKEv1 DEBUG]: Pitcher: received key delete msg, spi 0xb161983b
    Feb 28 13:41:29 [IKEv1 DEBUG]: Pitcher: received a key acquire message, spi 0x0
    Feb 28 13:41:29 [IKEv1]: Group = 216.203.46.252, IP = 216.203.46.252, IKE Initiator: New Phase 2, Intf backup, IKE Peer 216.203.46.252  local Proxy Address 10.133.133.0, remote Proxy Address 10.1.14.0,  Crypto map (outside_map)
    Feb 28 13:41:29 [IKEv1 DEBUG]: Group = 216.203.46.252, IP = 216.203.46.252, Oakley begin quick mode
    Feb 28 13:41:29 [IKEv1 DEBUG]: Group = 216.203.46.252, IP = 216.203.46.252, IKE got SPI from key engine: SPI = 0x9b973b9b
    Feb 28 13:41:29 [IKEv1 DEBUG]: Group = 216.203.46.252, IP = 216.203.46.252, oakley constucting quick mode
    Feb 28 13:41:29 [IKEv1 DEBUG]: Group = 216.203.46.252, IP = 216.203.46.252, constructing blank hash payload
    Feb 28 13:41:29 [IKEv1 DEBUG]: Group = 216.203.46.252, IP = 216.203.46.252, constructing IPSec SA payload
    Feb 28 13:41:29 [IKEv1 DEBUG]: Group = 216.203.46.252, IP = 216.203.46.252, constructing IPSec nonce payload
    Feb 28 13:41:29 [IKEv1 DEBUG]: Group = 216.203.46.252, IP = 216.203.46.252, constructing proxy ID
    Feb 28 13:41:29 [IKEv1 DEBUG]: Group = 216.203.46.252, IP = 216.203.46.252, Transmitting Proxy Id:
      Local subnet:  10.133.133.0  mask 255.255.255.0 Protocol 0  Port 0
      Remote subnet: 10.1.14.0  Mask 255.255.255.0 Protocol 0  Port 0
    Feb 28 13:41:29 [IKEv1 DEBUG]: Group = 216.203.46.252, IP = 216.203.46.252, constructing qm hash payload
    Feb 28 13:41:29 [IKEv1]: IP = 216.203.46.252, IKE_DECODE SENDING Message (msgid=150b2ab3) with payloads : HDR + HASH (8) + SA (1) + NONCE (10) + ID (5) + ID (5) + NONE (0) total length : 168
    Feb 28 13:41:29 [IKEv1]: IP = 216.203.46.252, IKE_DECODE RECEIVED Message (msgid=cabc11c) with payloads : HDR + HASH (8) + NOTIFY (11) + NONE (0) total length : 224
    Feb 28 13:41:29 [IKEv1 DEBUG]: Group = 216.203.46.252, IP = 216.203.46.252, processing hash payload
    Feb 28 13:41:29 [IKEv1 DEBUG]: Group = 216.203.46.252, IP = 216.203.46.252, processing notify payload
    Feb 28 13:41:29 [IKEv1]: Group = 216.203.46.252, IP = 216.203.46.252, Received non-routine Notify message: Invalid ID info (18)
    I suspect the configs don't match on both sides, but getting info from the other side of the tunnel is like pulling teeth.

Maybe you are looking for

  • Merging of multiple rows in an internal table as a single record

    Hi All, I have an internal table which has the following columns: text, date, time, user. it stores notes in the internal table. The problem is...when I save a note with multiple lines and spaces it saves each line of the note as a row in the interna

  • URGENT Different ways of creating portals (Daniel & subbu Have a look and answer)

    Hi all,      My primary aim is to run an existing application in a portal server. My application is running in weblogic6.1. I need to provide a link to that application from a portlet. I was going thro' the newsgroups and I found out the following re

  • Unusual interlacing problem

    Greetings, I recently shot a short 16mm film and got it telecined to DV NTSC with timecode/keycode window-burn. I imported the flex file I got from the lab into a Cinema Tools 4 database, then exported a batch capture list, and captured the footage i

  • Sync looks hanging in download phase in C$ALL_SNAPSHOTS (last item)

    The synchronizations are "hanged" for a long period on time in the download phase on the last 2 items: PI_APP_PUB_PROPERTIES C$ALL_SNAPSHOTS The time is bigger if the number of clients synchronizing at the same time is bigger as well. I have taken so

  • BAPI or FM for NCOP Transaction (To assign Cost Center to Org Unit)

    Hi, We are searching for a BAPI or any other means to assign Cost Center to Org Unit. recording  this transaction is not so useful because the screen fields are not recorded properly. Please advise if you had come across this transaction. Thanks in a