From netramet-owner  Tue Jan  4 19:14:41 2000
Received: (from majordom@localhost)
       by mailhost.auckland.ac.nz (8.9.2/8.9.2/8.9.2-ua) id TAA26130
       for netramet-outgoing; Tue, 4 Jan 2000 19:10:44 +1300 (NZDT)
Received: from www.hexaware.com ([198.138.182.2])
       by mailhost.auckland.ac.nz (8.9.2/8.9.2/8.9.2-ua) with ESMTP id TAA26121
       for <[email protected]>; Tue, 4 Jan 2000 19:10:40 +1300 (NZDT)
Received: from anand-manian ([192.168.25.131])
       by www.hexaware.com (8.9.3/8.8.5) with SMTP id BAA17275
       for <[email protected]>; Tue, 4 Jan 2000 01:15:23 -0500
Received: by localhost with Microsoft MAPI; Tue, 4 Jan 2000 11:44:27 +0530
Message-ID: <[email protected]>
From: Anand Manian <[email protected]>
Reply-To: "[email protected]" <[email protected]>
To: "'[email protected]'" <[email protected]>
Date: Tue, 4 Jan 2000 11:44:25 +0530
Organization: Hexaware Infosystems Ltd
X-Mailer: Microsoft Internet E-mail/MAPI - 8.0.0.4211
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Sender: [email protected]
Precedence: bulk

I just joined this mailing list. Is there a place where previous posintgs/emails are archived that I can refer to
to catch up?

Are there any FAQ's around for NeTraMet?

Thanks.

-ANand Manian
[email protected]

From netramet-owner  Thu Jan 27 19:05:16 2000
Received: (from majordom@localhost)
       by mailhost.auckland.ac.nz (8.9.2/8.9.2/8.9.2-ua) id TAA11012
       for netramet-outgoing; Thu, 27 Jan 2000 19:01:31 +1300 (NZDT)
Received: from xroads.vthrc.uq.edu.au (xroads.vthrc.uq.edu.au [130.102.4.16])
       by mailhost.auckland.ac.nz (8.9.2/8.9.2/8.9.2-ua) with ESMTP id TAA11001
       for <[email protected]>; Thu, 27 Jan 2000 19:01:28 +1300 (NZDT)
Received: (from fwtk@localhost)
       by xroads.vthrc.uq.edu.au (8.8.6/8.8.6) id OAA10384
       for <[email protected]>; Thu, 27 Jan 2000 14:08:20 +1000 (EST)
Received: from d-thomas-mac.vthrc.uq.edu.au(130.102.4.80) by xroads.vthrc.uq.edu.au via smap (V1.3)
       id smaa10376; Thu Jan 27 14:07:59 2000
X-Sender: [email protected]
Message-Id: <v02140b05b4b56e457f71@[130.102.4.80]>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Date: Thu, 27 Jan 2000 14:07:59 +1000
To: [email protected]
From: [email protected] (Danny Thomas)
Subject: does BSDi support RTFM ?
Sender: [email protected]
Precedence: bulk

I came across a mention of flow monitoring in a story about the lastest
version of the BSDi server, released in mid-December. Anyone know if they
use RTFM ? A search on the BSDi web-site didn't find any detail.



http://www.daemonnews.org/200001/bsdi.html

Flow Monitoring
===============
Flow monitoring enables a network administrator to monitor network traffic,
providing a valuable tool for designing and optimizing the network backbone
and studying network utilization. Network administrators usually pay tens
of thousands for a small PC with monitoring software to provide this
service. Using BSD/OS on a server, not only can the Network Administrator
monitor the network traffic, but the same machine can be used for a
firewall, web and ftp services, routing, etc. This is a far more cost
effective solution to this problem. In addition, no more lugging the
Monitoring PC around to different subnets. Just use BSD/OS on systems which
act as routers. Then from the privacy and convenience of your own office
you can monitor the traffic on numerous subnets.


cheers,
Danny Thomas



From netramet-owner  Thu Jan 27 22:14:56 2000
Received: (from majordom@localhost)
       by mailhost.auckland.ac.nz (8.9.2/8.9.2/8.9.2-ua) id WAA19906
       for netramet-outgoing; Thu, 27 Jan 2000 22:14:24 +1300 (NZDT)
Received: from xroads.vthrc.uq.edu.au (xroads.vthrc.uq.edu.au [130.102.4.16])
       by mailhost.auckland.ac.nz (8.9.2/8.9.2/8.9.2-ua) with ESMTP id WAA19900
       for <[email protected]>; Thu, 27 Jan 2000 22:14:20 +1300 (NZDT)
Received: (from fwtk@localhost)
       by xroads.vthrc.uq.edu.au (8.8.6/8.8.6) id TAA13949
       for <[email protected]>; Thu, 27 Jan 2000 19:14:18 +1000 (EST)
Received: from d-thomas-mac.vthrc.uq.edu.au(130.102.4.80) by xroads.vthrc.uq.edu.au via smap (V1.3)
       id sma013947; Thu Jan 27 19:14:00 2000
X-Sender: [email protected]
Message-Id: <v02140b07b4b5ba1f53c2@[130.102.4.80]>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Date: Thu, 27 Jan 2000 19:14:01 +1000
To: [email protected]
From: [email protected] (Danny Thomas)
Subject: rephrased: does BSDi support RTFM ?
Sender: [email protected]
Precedence: bulk

obviously I didn't phrase my question well.

I don't have BSDi, nor any intention of buying it. Not that there's
anything bad about the product (wasn't it the first commercial unix with
ip6 support?)

BSDi claims to offer flow monitoring as a new feature in it's SuperServer
4.1 released a month ago. I found that interesting, and perhaps indicative
RTFM might become a feature appearing in more commercial systems (eg even
LAN switches). Since the BSDi web-pages don't seem to offer any details, I
was wondering whether anyone knew:

1) is that flow-monitoring RTFM, per the RFCs
2) is it based on NetRaMet
3) does it only work with flows measured on BSDi systems
  or can you integrate it with other systems
4) does BSDi any tools on top of raw flow measurements
5) is there anything particularly interesting about it


[email protected]:
>If BSDi supports promiscious mode for your NIC, you should be able
>to run NeTraMet.  I run it on OpenBSD boxes with nary a problem.


"M.R. Mackenbach" <[email protected]> offered:
>Do you know the meaning of RTFM ?
>
>It's a shorty for "Read The F*ckin Manual" ......



From netramet-owner  Sat Jan 29 11:56:07 2000
Received: (from majordom@localhost)
       by mailhost.auckland.ac.nz (8.9.2/8.9.2/8.9.2-ua) id LAA12216
       for netramet-outgoing; Sat, 29 Jan 2000 11:51:34 +1300 (NZDT)
Received: from postal.sdsc.edu (IDENT:61Sx/[email protected] [132.249.40.114])
       by mailhost.auckland.ac.nz (8.9.2/8.9.2/8.9.2-ua) with ESMTP id LAA12210;
       Sat, 29 Jan 2000 11:51:28 +1300 (NZDT)
Received: from lt.itss.auckland.ac.nz ([email protected] [192.172.226.49])
       by postal.sdsc.edu (8.9.3/8.9.3/SDSCserver-16) with ESMTP id OAA01111;
       Fri, 28 Jan 2000 14:51:19 -0800 (PST)
From: Nevil Brownlee <[email protected]>
Date: Fri, 28 Jan 2000 14:51:41 +0000
To: Marcelo Pias <[email protected]>
Subject: Re: NeTraMet under windows
Cc: [email protected], [email protected]
In-Reply-To: <[email protected]>
References: <[email protected]> <[email protected]>
Message-ID: <[email protected]>
Priority: NORMAL
X-Mailer: Execmail for Linux 5.1 Build (9)
MIME-Version: 1.0
Content-Type: Text/Plain; charset="us-ascii"
Sender: [email protected]
Precedence: bulk

Hello Marcello:

>       I was wondering if you know any implementation of NeTraMet for
> Windows (95,98...). I tried to use the PC version of NeTraMet but it
> didn't work under Windows 98. I would be interested in the NeTraMet
> running together with other applications (browsers, email programs...) and
> measuring this traffic, basically on the end side.

I don't know of one.  It would be easy to port NeMaC and friends,
since they only need BSD sockets (Winsock shouldn't be too hard).
To port NeTraMet requires you to observe packets on an interface
in promiscuous mode, ideally by porting the libpcap library to
Windows.  IF you have a version of Winsock which allows
promiscuous mode, maybe it wouldn't be too hard.  But, as I said,
I don't know of anyone who's done this yet.

Cheers, Nevil

+---------------------------------------------------------------------+
| Nevil Brownlee                     Director, Technology Development |
| Phone: +64 9 373 7599 x8941        ITSS, The University of Auckland |
|   FAX: +64 9 373 7021      Private Bag 92019, Auckland, New Zealand |
+---------------------------------------------------------------------L