Greetings once again. I have a question I hope some networking fellow can help with. I have a NAT box (sarnold) and a single box hidden behind it (amidala) -- and they won't stop talking to each other. Here is a typical tcpdump output:
21:40:25.447332 sarnold.25682 > amidala.6000: P 65829:65857(28) ack 0 win 8192 (DF) 21:40:25.448015 sarnold.25682 > amidala.6000: P 65857:65969(112) ack 0 win 8192 (DF) 21:40:25.448037 sarnold.25682 > amidala.6000: P 65969:65997(28) ack 0 win 8192 (DF) 21:40:25.448077 sarnold.25682 > amidala.6000: P 65997:66025(28) ack 0 win 8192 (DF) 21:40:25.448798 sarnold.25626 > amidala.6000: P 5293:5377(84) ack 0 win 8192 (DF) 21:40:25.448833 sarnold.25626 > amidala.6000: P 5377:5405(28) ack 0 win 8192 (DF) 21:40:25.449165 sarnold.25626 > amidala.6000: P 5405:5433(28) ack 0 win 8192 (DF) 21:40:25.449207 sarnold.25626 > amidala.6000: P 5433:5461(28) ack 0 win 8192 (DF) 21:40:25.449242 sarnold.25626 > amidala.6000: P 5461:5489(28) ack 0 win 8192 (DF) 21:40:25.458153 amidala.6000 > sarnold.25682: . ack 66025 win 32120 (DF) 21:40:25.468147 amidala.6000 > sarnold.25626: . ack 5489 win 32120 (DF) Does anyone have any clue what is going on? I have two small little programs, that don't update that often, ssh2 displayed on amidala, running on sarnold -- is this level of traffic normal? (the programs are wmifs, one for each ethernet device..) Should I be worried about this level of traffic? It seems high.. thanks. :) -- Seth Arnold | http://www.willamette.edu/~sarnold/ Hate spam? See http://maps.vix.com/rbl/ for help Hi! I'm a .signature virus! Copy me into your ~/.signature to help me spread!