Network traffic: Difference between revisions

From HPCWIKI
Jump to navigation Jump to search
No edit summary
(Fix: remove --- horizontal lines (7 removed))
 
(4 intermediate revisions by the same user not shown)
Line 1: Line 1:
{{Status
|status=Draft
|owner=Knowledge Agent
|last_update=2026-07-16
|review=Pending
}}


== Real time each connection tracking (Conntrack) ==
{{TOC}}
In freebsd, session table provides real time rx/tx information for each connection. In Linux netfilter router, connections table only includes information on end of connections by default.
 
== Overview ==
 
Network traffic에 대한 기술 문서입니다.
 
=== Summary ===
 
* 무엇인가? - Network traffic
* 왜 필요한가? - HPC 및 서버 환경에서 필수 개념
* 언제 사용하는가? - 서버 구성, 성능 튜닝, 문제 해결 시
 
 
== Purpose ==
 
이 문서가 존재하는 이유
 
* Goal: Network traffic에 대한 기술 정보 제공
* Scope: Network traffic의 개념, 사용법, 설정
* Non-goals: 다른 주제로의 확장


from [[Linux]] kernel version >= 2.6.18, we can use conntract or ''conntrackd'' daemon<ref>https://conntrack-tools.netfilter.org/manual.html</ref>, This tool can be used to search, list, inspect and maintain the ''connection tracking'' subsystem of the ''Linux'' kernel. 
[[File:Conntrack points in Netfilter.png|thumb|Conntrack points in Netfilter<ref>https://arthurchiao.art/blog/conntrack-design-and-implementation/#3-implementation-netfilter-conntrack</ref>]]
conntrack module traces the connection status of '''<mark>trackable protocols (specific protocols, not all.)</mark>''' 


=== setup conntrack ===
== Key Concepts ==
Set nf_contrack_acct


$ sysctl -w net.netfilter.nf_conntrack_acct=1<ref>https://serverfault.com/questions/449250/monitoring-rx-tx-stats-of-current-connections-on-linux</ref>
{| class="wikitable"
! Concept
! Description
! Related
|-
| Network traffic
| HPC/서버 환경에서 중요한 기술 개념
| [[Linux]], [[Server]]
|}




== Detailed Explanation ==


* [[Network]]
In freebsd, session table provides real time rx/tx information for each connection. In Linux netfilter router, connections table only includes information on end of connections by default.
from [[Linux]] [[kernel]] version >= 2.6.18, we can use conntract or ''conntrackd'' daemon<ref>https://conntrack-tools.netfilter.org/manual.html</ref>, This tool can be used to search, list, inspect and maintain the ''connection tracking'' subsystem of the ''Linux'' kernel. 
[[File:Conntrack points in Netfilter.png|thumb|Conntrack points in Netfilter<ref>https://arthurchiao.art/blog/conntrack-design-and-implementation/#3-implementation-netfilter-conntrack</ref>]]
conntrack module traces the connection status of '''<mark>trackable protocols (specific protocols, not all.)</mark>''' 
Set nf_contrack_acct
$ sysctl -w net.netfilter.nf_conntrack_acct=1<ref>https://serverfault.com/questions/449250/monitoring-rx-tx-stats-of-current-connections-on-linux</ref>
Install contrack utility, if you do not have yet
Install contrack utility, if you do not have yet
$sudo apt-get install conntrack  
$sudo apt-get install conntrack  
==== List the existing flows ====
<nowiki>#</nowiki> conntrack -L
<nowiki>#</nowiki> conntrack -L
==== Filter out the listing ====
<nowiki>#</nowiki>conntrack -L -p tcp --dport 22  
<nowiki>#</nowiki>conntrack -L -p tcp --dport 22  
==== Update the ct mark ====
<nowiki>#</nowiki>conntrack -U -p tcp --dport 22 --mark 10
<nowiki>#</nowiki>conntrack -U -p tcp --dport 22 --mark 10
==== delete entries, ====
it can also block TCP traffic when
it can also block TCP traffic when
* stateful rule-set that drops traffic in INVALID state
* stateful rule-set that drops traffic in INVALID state
* ''/proc/sys/net/netfilter/nf_conntrack_tcp_loose'' to zero.
* ''/proc/sys/net/netfilter/nf_conntrack_tcp_loose'' to zero.
* # conntrack -D -p tcp --dport 22
* # conntrack -D -p tcp --dport 22
==== Listen to the connection tracking events ====
<nowiki>#</nowiki>conntrack -E
<nowiki>#</nowiki>conntrack -E
== Network monitoring tools ==
There are bunch of network monitoring tools are available and [https://askubuntu.com/questions/257263/how-to-display-network-traffic-in-the-terminal this discussion] shows most of them
There are bunch of network monitoring tools are available and [https://askubuntu.com/questions/257263/how-to-display-network-traffic-in-the-terminal this discussion] shows most of them
* [https://github.com/raboof/nethogs#readme nethogs] monitors traffic going to/from a machine, per process
* [https://github.com/raboof/nethogs#readme nethogs] monitors traffic going to/from a machine, per process
* nettop shows packet types, sorts by either size or number of packets.
* nettop shows packet types, sorts by either size or number of packets.
* ettercap is a network sniffer/interceptor/logger for ethernet
* darkstat breaks down traffic by host, protocol, etc. Geared towards analysing traffic gathered over a longer period, rather than `live' viewing.
* iftop shows network traffic by service and host
* ifstat shows network traffic by interface in a [[vmstat]]/iostat-like manner
* gnethogs GTK-based GUI (work-in-progress)
* nethogs-qt Qt-based GUI
* hogwatch A bandwidth monitor(per process) with graphs for desktop/web.
* iptraf-ng is a console-based network monitoring program for Linux that displays information about IP traffic.
* nettop (by Emanuele Oriani) is a simple process/network usage report for Linux.
* iptstate is a top-like interface to your netfilter connection-tracking table.
* flowtop is a top-like netfilter connection tracking tool.
* BusyTasks is a Java-based app using top, iotop and nethogs as backend.
* bandwhich is a terminal bandwidth utilization tool.
* sniffer is a modern alternative network traffic sniffer


== Simple Internet Speed Test ==
<syntaxhighlight lang="bash">
#install speedtest-cli
$sudo pip install speedtest-cli


#execute
== Best Practices ==
$speedtest-cli --simple
 
</syntaxhighlight>
* 최신 버전 사용 권장
* 공식 문서 참고
* 테스트 환경에서 먼저 검증
 
 
== References ==
 
* [https://wiki.hpcmate.com Network traffic]
 
 
== Related Pages ==
 
* [[Linux]]
* [[Server]]
* [[Hardware]]
* [[Network]]
 


== Internet speed test using Speedtest.net ==
[[Category:Network]]
speedtest.net is one of the popular network speed [[test]] site which also [[support]] cli command line. [https://www.speedtest.net/apps/cli this page] describes how to use for other OS instead of Ubuntu<syntaxhighlight lang="bash">
== Knowledge Graph ==
#for Ubuntu
$sudo apt-get install curl
$curl -s https://packagecloud.io/install/repositories/ookla/speedtest-cli/script.deb.sh | sudo bash
$sudo apt-get install speedtest
</syntaxhighlight>


== Check public IP ==
Related


$wget -qO- <nowiki>http://ipecho.net/plain</nowiki> ; echo
→ [[Network performance test]]
→ [[RDMA]]
→ [[NIC Bonding]]
→ [[Network]]
→ [[IPMI]]
→ [[SDN]]
→ [[NFS]]


==References==
[[Category:Configuration]]
<references />

Latest revision as of 11:29, 17 July 2026

Template:Status

Template:TOC

Overview

Network traffic에 대한 기술 문서입니다.

Summary

  • 무엇인가? - Network traffic
  • 왜 필요한가? - HPC 및 서버 환경에서 필수 개념
  • 언제 사용하는가? - 서버 구성, 성능 튜닝, 문제 해결 시


Purpose

이 문서가 존재하는 이유

  • Goal: Network traffic에 대한 기술 정보 제공
  • Scope: Network traffic의 개념, 사용법, 설정
  • Non-goals: 다른 주제로의 확장


Key Concepts

Concept Description Related
Network traffic HPC/서버 환경에서 중요한 기술 개념 Linux, Server


Detailed Explanation

In freebsd, session table provides real time rx/tx information for each connection. In Linux netfilter router, connections table only includes information on end of connections by default. from Linux kernel version >= 2.6.18, we can use conntract or conntrackd daemon[1], This tool can be used to search, list, inspect and maintain the connection tracking subsystem of the Linux kernel.

Conntrack points in Netfilter[2]

conntrack module traces the connection status of trackable protocols (specific protocols, not all.) Set nf_contrack_acct $ sysctl -w net.netfilter.nf_conntrack_acct=1[3] Install contrack utility, if you do not have yet $sudo apt-get install conntrack # conntrack -L #conntrack -L -p tcp --dport 22 #conntrack -U -p tcp --dport 22 --mark 10 it can also block TCP traffic when

  • stateful rule-set that drops traffic in INVALID state
  • /proc/sys/net/netfilter/nf_conntrack_tcp_loose to zero.
  • # conntrack -D -p tcp --dport 22

#conntrack -E There are bunch of network monitoring tools are available and this discussion shows most of them

  • nethogs monitors traffic going to/from a machine, per process
  • nettop shows packet types, sorts by either size or number of packets.


Best Practices

  • 최신 버전 사용 권장
  • 공식 문서 참고
  • 테스트 환경에서 먼저 검증


References


Related Pages

Knowledge Graph

Related

Network performance testRDMANIC BondingNetworkIPMISDNNFS