(C) 1998-2011 - Luca Deri  
Please enable make sure that the ntop html/ directory is properly installed

 

 

Info about 163.30.44.1

IP Address163.30.44.1 [unicast] [ Purge Asset ]
Custom Host Name
First/Last SeenTue Jun 17 00:00:05 2025  -  Tue Jun 17 06:46:46 2025 [Inactive since 2 sec]
Autonomous System1659 [Tiawan Academic Network (TANet) Information Center]
Subnet163.30.44.0/24
MAC Address Network Interface Card (NIC)10:C3:7B:47:57:9A  
Origin AS1659
Host LocationLocal (inside specified/local subnet or known network list)
Physical LocationTaoyüan, Taiwan Flag for Taiwan (TW)   
IP TTL (Time to Live)64:64 [~0 hop(s)]
Total Data Sent10.3 MBytes/57,977 Pkts/0 Retran. Pkts [0%]
Broadcast Pkts Sent598 Pkts
Data Sent Stats
Local 26.5 %
  
Rem 73.5 %
IP vs. Non-IP Sent
IP 100 %
 
Non-IP 0 %
Total Data Rcvd12.2 MBytes/57,473 Pkts/0 Retran. Pkts [0%]
Data Rcvd Stats
Local 9.3 %
  
Rem 90.7 %
IP vs. Non-IP Rcvd
IP 100 %
 
Non-IP 0 %
Sent vs. Rcvd Pkts
Sent 50.2 %
  
Rcvd 49.8 %
Sent vs. Rcvd Data
Sent 45.7 %
  
Rcvd 54.3 %
Used Subnet Routers 4C:77:6D:62:EA:41 Network Card
Host TypeName Server DNS
SMTP (Mail) Server Mail (SMTP)
POP Server 
IMAP Server 
HTTP Server HTTP Server
Host Healthness (Risk Flags) High Risk Medium Risk Low Risk
  1. Medium RiskWrong network mask or bridging enabled
  2. Medium RiskSuspicious activities: too many host contacts
  3. Low RiskUnexpected packets (e.g. traffic to closed port or connection reset):
    [Sent: udp to closed] [Rcvd: rst] [Rcvd: port unreac] [Rcvd: admin prohib] 

 

Host Traffic Stats

TimeTot. Traffic Sent% Traffic SentTot. Traffic Rcvd% Traffic Rcvd
6 AM 1.2 MBytes12.0 %1.1 MBytes8.7 %
5 AM 1.7 MBytes16.9 %1.4 MBytes11.8 %
4 AM 1.8 MBytes17.4 %2.0 MBytes16.3 %
3 AM 1.7 MBytes16.9 %1.4 MBytes11.7 %
2 AM 1.2 MBytes11.3 %1.5 MBytes12.2 %
1 AM 1.3 MBytes12.6 %3.4 MBytes27.9 %
12 AM 1.3 MBytes12.8 %1.4 MBytes11.4 %
11 PM 00.0 %00.0 %
10 PM 00.0 %00.0 %
9 PM 00.0 %00.0 %
8 PM 00.0 %00.0 %
7 PM 00.0 %00.0 %
6 PM 00.0 %00.0 %
5 PM 00.0 %00.0 %
4 PM 00.0 %00.0 %
3 PM 00.0 %00.0 %
2 PM 00.0 %00.0 %
1 PM 00.0 %00.0 %
12 PM 00.0 %00.0 %
11 AM 00.0 %00.0 %
10 AM 00.0 %00.0 %
9 AM 00.0 %00.0 %
8 AM 00.0 %00.0 %
7 AM 00.0 %00.0 %
Total

 

Packet Statistics

TCP ConnectionsDirected toRcvd From
Attempted792 3,902
Established319 [40 %] 1,091 [28 %]
Terminated0  124

TCP FlagsPkts SentPkts Rcvd
SYN792 3,902
RST|ACK1,999 179
RST2 1,851
NULL0  65

AnomalyPkts Sent toPkts Rcvd from
UDP Pkt to Closed Port113 83
Tiny Fragments0  7
Closed Empty TCP Conn.0  124
ICMP Port Unreachable83 113
ICMP Administratively Prohibited0  4

ARPPacket
Request Sent0
Reply Rcvd58 (0.0 %)
Reply Sent1,341

 

Protocol Distribution

ProtocolData SentData Rcvd
TCP4.7 MBytes
45%

 

3.0 MBytes
24%

 

UDP5.5 MBytes
53%

 

9.1 MBytes
74%

 

ICMP58.1 KBytes  43.8 KBytes 
(R)ARP46.8 KBytes  60.4 KBytes 
Protocol Distribution
IP Distribution

 

ICMP Traffic

TypePkt SentPkt Rcvd
Echo Request2460
Echo Reply0246
Unreach83117
Redirect4230
Time Exceeded01

 

IP Fragments Distribution

ProtocolData SentData Rcvd
UDP2.0 KBytes100% 10.9 KBytes100
Fragment DistributionSent Fragment Distribution for 163.30.44.1-65535Received Fragment Distribution for 163.30.44.1-65535
IP Fragment DistributionSent IP Fragment Distribution for 163.30.44.1-65535Received IP Fragment Distribution for 163.30.44.1-65535

 

Last Contacted Peers

Sent ToIP Address
202.12.27.33 202.12.27.33 
192.48.79.30 192.48.79.30 
163.30.44.24 163.30.44.24 
172.105.65.55 172.105.65.55 
163.30.0.1 163.30.0.1 
192.26.92.30 192.26.92.30 
192.5.6.30 192.5.6.30 
172.105.169.72 172.105.169.72 
Total Contacts19465
Received FromIP Address
192.48.79.30 192.48.79.30 
192.58.128.30 192.58.128.30 
163.30.0.1 163.30.0.1 
172.105.65.55 172.105.65.55 
192.26.92.30 192.26.92.30 
192.5.6.30 192.5.6.30 
172.105.169.72 172.105.169.72 
163.30.44.24 163.30.44.24 
Total Contacts17822

 

HTTP Virtual Hosts Traffic

Virtual HostSentRcvd
www.youporn.com44 131 
6.1 KBytes 2.6 KBytes 
www.tyes.tyc.edu.tw169.3 KBytes 205.7 KBytes 
163.30.44.1:8066.4 KBytes 68.5 KBytes 
dns.tyes.tyc.edu.tw86.6 KBytes 82.9 KBytes 
host1.tyes.tyc.edu.tw1.4 MBytes 1.6 MBytes 
163.30.44.1303.2 KBytes 293.0 KBytes 
NOTE: The above table is not updated in realtime but when connections are terminated.

 

IP Service Stats: Client Role

 # Loc. Req. Sent# Rem. Req. Sent# Pos. Reply Rcvd# Neg. Reply RcvdLocal RndTripRem RndTrip
DNS00.0%32,408100.0%24,86780.0%6,04719.0%0.0 ms - 0.0 ms1.0 ms - 5.0 sec
HTTP00.0%3100.0%150.0%150.0%0.0 ms - 0.0 ms0.0 ms - 0.0 ms

 

IP Service Stats: Server Role

 # Loc. Req. Rcvd# Rem. Req. Rcvd# Pos. Reply Sent# Neg. Reply SentLocal RndTripRem RndTrip
DNS12,51899.0%200.0%4,91339.0%7,55560.0%0.0 ms - 30.0 sec0.1 ms - 0.2 ms
HTTP00.0%247100.0%433.0%866.0%0.0 ms - 0.0 ms0.0 ms - 0.0 ms

 

TCP/UDP Service/Port Usage

IP ServicePort# Client Sess.Last Client Peer# Server Sess.Last Server Peer
2222  1/2120.64.105.237
2525443/169.3 KBytes203.145.212.9 798/170.0 KBytes45.112.84.5
535363391/8.4 MBytes163.30.0.1 25005/2.6 MBytes163.30.44.24
http801277/1.8 MBytes192.50.199.248 1189/945.3 KBytes78.47.173.76
8888  1/40165.154.246.252
pop-3110  25/1.9 KBytes206.168.34.122
1231238/384118.163.81.61 5/174192.210.187.83
143143  18/2.2 KBytes206.168.34.61
snmp161  18/3.1 KBytes135.237.125.195
snmp-trap162  1/60165.154.246.243
199199  6/36445.79.128.205
389389  1/5171.6.135.131
391391  1/60165.154.237.251
427427  2/63147.185.132.213
https443  2/1.3 KBytes165.154.246.249
523523  1/20165.154.246.249
587587  34/3.3 KBytes147.185.132.49
873873  73/1.8 KBytes34.140.38.148
993993  1/12820.168.122.88

 

TCP/UDP - Traffic on Other Ports

Client PortServer Port

 

TCP/UDP Recently Used Ports

Client PortServer Port

 

Recent Sessions: Network Delay

Client ModeServer Mode
Last TimeServiceLast Server ContactClient Delay [min/avg/max]
Tue Jun 17 01:24:43 2025 HTTP192.50.199.248 0.01/0.03/0.07 ms
Last TimeServiceLast Client ContactServer Delay [min/avg/max]
Tue Jun 17 06:44:21 2025 HTTP66.249.74.75 0.01/0.02/0.04 ms
Tue Jun 17 04:39:40 2025 Mail206.168.34.122 0.01/0.02/0.03 ms
  • Scenario: client <--> ntop <--> server
  • Client Delay: the network delay (computed as RTT/2) taken
    by a packet sent by the client to reach ntop
  • Server Delay: the network delay (computed as RTT/2) taken
    by a packet sent by the server to reach ntop
  • All times are majored during TCP 3-way handshake

 

Active Sessions

ProtoClientServerData Sent/RcvdActive SinceDurationInactiveClient/Server Nw DelayL7 Proto
TCP216.73.216.30 :44685 163.30.44.1 Network Card DNS Mail (SMTP) HTTP Server Medium Risk :300095510.6 KBytesTue Jun 17 06:45:50 20251 sec57 sec90.25 ms0.02 ms 

The color of the host link indicates how recently the host was FIRST seen
  0 to 5 minutes     5 to 15 minutes     15 to 30 minutes     30 to 60 minutes     60+ minutes