Linux Netfilter discussions
 help / color / mirror / Atom feed
From: "Simon Garner" <sgarner@expio.co.nz>
To: SBlaze <dagent.geo@yahoo.com>, netfilter@lists.netfilter.org
Subject: Re: a sort of n00b question here but I'ld like to know.
Date: Wed, 22 Oct 2003 10:12:19 +1300	[thread overview]
Message-ID: <00ea01c39818$162e5c80$0301a8c0@SIMON> (raw)
In-Reply-To: 20031021181138.49502.qmail@web40202.mail.yahoo.com

On Wednesday, October 22, 2003 7:11 AM [GMT+1200=NZT],
SBlaze <dagent.geo@yahoo.com> wrote:

>
> Wouldn't ntop be considered a "probing" tool?
>

I wouldn't consider it a probing tool... something like nmap would be
probing, ntop just listens. And although it puts your eth into
promiscuous mode, I wouldn't call it a packet sniffer since it won't
tell you the contents of any packets, only where they're going and how
big they are etc. I don't think you have anything to worry about.

Now I have no experience with cable or cable modems (they're practically
non-existent over here) but wouldn't running this on your linux box only
show you whatever data your cable modem is sending to you anyway...
you'd need to put the *cable modem* into promiscuous mode (or
equivalent) to actually receive any data you shouldn't.

>
> And getting back to my original reason and question for this post. How
> statistically can you see just how much iptables/netfilter is using
> of system resources?
>

I think we're agreed that the level of data you're seeing wouldn't cause
any problems CPU-wise. You can see kernel CPU usage as "system CPU%" in
top and vmstat and they're saying 0, which would be expected.

-Simon



  reply	other threads:[~2003-10-21 21:12 UTC|newest]

Thread overview: 18+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2003-10-21  0:02 a sort of n00b question here but I'ld like to know Daniel Chemko
2003-10-21  0:41 ` SBlaze
2003-10-21  1:08   ` Simon Garner
2003-10-21  1:24     ` SBlaze
2003-10-21  1:49       ` Simon Garner
2003-10-21  2:03         ` SBlaze
2003-10-21  2:33           ` Simon Garner
2003-10-21  2:49             ` SBlaze
2003-10-21  4:46               ` Alistair Tonner
2003-10-21 18:11                 ` SBlaze
2003-10-21 21:12                   ` Simon Garner [this message]
2003-10-21 22:36                     ` SBlaze
2003-10-22  0:08                   ` Alistair Tonner
2003-10-21  2:34           ` Jeffrey Laramie
2003-10-21  2:56             ` SBlaze
  -- strict thread matches above, loose matches on Subject: below --
2003-10-21 19:44 Daniel Chemko
2003-10-20 23:37 Eric Marchionni
2003-10-20  1:39 SBlaze

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to='00ea01c39818$162e5c80$0301a8c0@SIMON' \
    --to=sgarner@expio.co.nz \
    --cc=dagent.geo@yahoo.com \
    --cc=netfilter@lists.netfilter.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox