(C) 1998-2011 - Luca Deri  
Please enable make sure that the ntop html/ directory is properly installed

 

 

Info about 163.30.44.1

IP Address163.30.44.1 [unicast - multihomed Multihomed] [ Purge Asset ]
Multihomed Addresses 
    Custom Host Name
    First/Last SeenMon Jun 16 00:00:11 2025  -  Mon Jun 16 23:04:20 2025 [Inactive since 1 sec]
    Autonomous System1659 [Tiawan Academic Network (TANet) Information Center]
    Subnet163.30.44.0/24
    Main Host MAC Address10:C3:7B:47:57:9A 
    Origin AS1659
    Host LocationLocal (inside specified/local subnet or known network list)
    Physical LocationTaoyüan, Taiwan Flag for Taiwan (TW)   
    IP TTL (Time to Live)63:127 [~0 hop(s)]
    Total Data Sent87.8 MBytes/237,253 Pkts/0 Retran. Pkts [0%]
    Broadcast Pkts Sent7,888 Pkts
    Data Sent Stats
    Local 10.6 %
      
    Rem 89.4 %
    IP vs. Non-IP Sent
    IP 100 %
     
    Non-IP 0 %
    Total Data Rcvd44.3 MBytes/211,659 Pkts/0 Retran. Pkts [0%]
    Data Rcvd Stats
    Local 9.8 %
      
    Rem 90.2 %
    IP vs. Non-IP Rcvd
    IP 100 %
     
    Non-IP 0 %
    Sent vs. Rcvd Pkts
    Sent 52.9 %
      
    Rcvd 47.1 %
    Sent vs. Rcvd Data
    Sent 66.5 %
      
    Rcvd 33.5 %
    Used Subnet Routers 4C:77:6D:62:EA:41 Network Card
    Host TypeName Server DNS
    VoIP Host VoIP
    SMTP (Mail) Server Mail (SMTP)
    POP Server 
    IMAP Server 
    HTTP Server HTTP Server
    Host Healthness (Risk Flags) High Risk Medium Risk Low Risk
    1. Medium RiskWrong network mask or bridging enabled
    2. Medium RiskSuspicious activities: too many host contacts
    3. Low RiskUnexpected packets (e.g. traffic to closed port or connection reset):
      [Sent: udp to closed] [Rcvd: rst] [Rcvd: port unreac] [Rcvd: admin prohib] 

     

    Host Traffic Stats

    TimeTot. Traffic Sent% Traffic SentTot. Traffic Rcvd% Traffic Rcvd
    11 PM 58.7 KBytes0.1 %69.5 KBytes0.2 %
    10 PM 2.4 MBytes2.8 %1.5 MBytes3.5 %
    9 PM 4.1 MBytes4.7 %1.6 MBytes3.7 %
    8 PM 3.0 MBytes3.4 %2.3 MBytes5.1 %
    7 PM 1.7 MBytes1.9 %3.3 MBytes7.4 %
    6 PM 3.4 MBytes3.8 %1.5 MBytes3.4 %
    5 PM 3.9 MBytes4.4 %1.7 MBytes3.9 %
    4 PM 1.3 MBytes1.5 %1.5 MBytes3.4 %
    3 PM 3.5 MBytes4.0 %1.8 MBytes4.0 %
    2 PM 2.0 MBytes2.3 %1.6 MBytes3.6 %
    1 PM 2.2 MBytes2.5 %3.4 MBytes7.7 %
    12 PM 1.2 MBytes1.4 %1.5 MBytes3.5 %
    11 AM 2.4 MBytes2.7 %1.4 MBytes3.1 %
    10 AM 1.1 MBytes1.3 %1.3 MBytes2.9 %
    9 AM 1.1 MBytes1.2 %1.3 MBytes3.0 %
    8 AM 11.1 MBytes12.6 %1.8 MBytes4.0 %
    7 AM 11.8 MBytes13.4 %3.5 MBytes7.9 %
    6 AM 3.0 MBytes3.4 %1.4 MBytes3.1 %
    5 AM 5.9 MBytes6.7 %1.6 MBytes3.6 %
    4 AM 4.5 MBytes5.2 %1.8 MBytes4.0 %
    3 AM 3.7 MBytes4.2 %1.6 MBytes3.7 %
    2 AM 8.8 MBytes10.1 %1.9 MBytes4.2 %
    1 AM 3.5 MBytes4.0 %3.4 MBytes7.8 %
    12 AM 2.2 MBytes2.5 %1.6 MBytes3.7 %
    Total

     

    Packet Statistics

    TCP ConnectionsDirected toRcvd From
    Attempted1,560 12,792
    Established648 [42 %] 2,856 [22 %]
    Terminated0  452

    TCP FlagsPkts SentPkts Rcvd
    SYN1,560 12,792
    RST|ACK7,700 381
    RST30 2,427
    NULL0  246

    AnomalyPkts Sent toPkts Rcvd from
    UDP Pkt to Closed Port228 334
    UDP Pkt Disgnostic Port0  4
    TCP Pkt Disgnostic Port5 8
    Tiny Fragments0  12
    Closed Empty TCP Conn.0  452
    ICMP Port Unreachable334 228
    ICMP Administratively Prohibited0  4

    ARPPacket
    Request Sent0
    Reply Rcvd197 (0.0 %)
    Reply Sent4,478

     

    Protocol Distribution

    ProtocolData SentData Rcvd
    TCP32.2 MBytes
    36%

     

    13.6 MBytes
    30%

     

    UDP55.2 MBytes
    62%

     

    30.4 MBytes
    68%

     

    ICMP202.6 KBytes  164.6 KBytes 
    IPsec0.0 KBytes  0.6 KBytes 
    (R)ARP155.6 KBytes  203.3 KBytes 
    Other (Non IP)0.0 KBytes  0.2 KBytes 
    Protocol Distribution
    IP Distribution

     

    Unknown Protocols

    Data SentData Rcvd
     
  1. IP Protocol: 0x41  
  2.  

    ICMP Traffic

    TypePkt SentPkt Rcvd
    Echo Request8310
    Echo Reply0831
    Unreach334232
    Redirect1,4580
    Time Exceeded046

     

    IP Fragments Distribution

    ProtocolData SentData Rcvd
    UDP38.4 MBytes100% 22.3 KBytes100
    Fragment DistributionSent Fragment Distribution for 163.30.44.1-65535Received Fragment Distribution for 163.30.44.1-65535
    IP Fragment DistributionSent IP Fragment Distribution for 163.30.44.1-65535Received IP Fragment Distribution for 163.30.44.1-65535

     

    Last Contacted Peers

    Sent ToIP Address
    193.34.212.110 193.34.212.110 
    163.30.0.1 163.30.0.1 
    216.73.216.30 216.73.216.30 
    205.251.198.171 205.251.198.171 
    205.251.196.113 205.251.196.113 
    205.251.199.181 205.251.199.181 
    205.251.196.101 205.251.196.101 
    fe80::7933:6ab8:a11f fe80::7933:6ab8:a11f 
    Total Contacts59876
    Received FromIP Address
    43.133.191.169 43.133.191.169 
    193.34.212.110 193.34.212.110 
    216.73.216.30 216.73.216.30 
    fe80::7933:6ab8:a11f fe80::7933:6ab8:a11f 
    205.251.196.113 205.251.196.113 
    205.251.198.171 205.251.198.171 
    205.251.199.181 205.251.199.181 
    205.251.196.101 205.251.196.101 
    Total Contacts56585

     

    HTTP Virtual Hosts Traffic

    Virtual HostSentRcvd
    dns.tyes.tyc.edu.tw4.0 KBytes 3.0 KBytes 
    www.youporn.com44 131 
    163.30.44.1:80105.0 KBytes 100.8 KBytes 
    www.tyes.tyc.edu.tw65.9 MBytes 61.4 MBytes 
    163.30.44.12.2 MBytes 2.2 MBytes 
    host1.tyes.tyc.edu.tw41.6 MBytes 40.8 MBytes 
    NOTE: The above table is not updated in realtime but when connections are terminated.

     

    IP Service Stats: Client Role

     # Loc. Req. Sent# Rem. Req. Sent# Pos. Reply Rcvd# Neg. Reply RcvdLocal RndTripRem RndTrip
    DNS00.0%99,006100.0%78,47580.0%18,84719.0%0.0 ms - 0.0 ms0.0 ms - 5.0 sec
    HTTP00.0%9100.0%450.0%450.0%0.0 ms - 0.0 ms0.0 ms - 0.0 ms

     

    IP Service Stats: Server Role

     # Loc. Req. Rcvd# Rem. Req. Rcvd# Pos. Reply Sent# Neg. Reply SentLocal RndTripRem RndTrip
    DNS39,51799.0%280.0%14,91437.0%24,53762.0%0.0 ms - 30.0 sec0.0 ms - 0.1 ms
    HTTP00.0%1,203100.0%523.0%1676.0%0.0 ms - 0.0 ms0.0 ms - 0.0 ms

     

    TCP/UDP Service/Port Usage

    IP ServicePort# Client Sess.Last Client Peer# Server Sess.Last Server Peer
    77  2/3164.62.197.35
    1111  1/165.49.1.58
    1313  1/165.49.1.81
    1717  1/165.49.1.55
    1919  1/164.62.156.79
    ftp21  1/2120.84.68.210
    telnet23  1/21135.233.112.102
    25251186/197.5 KBytes210.61.188.68 2347/1.6 MBytes162.241.143.174
    3737  1/164.62.197.32
    535365443/26.5 MBytes205.251.196.101 12726/8.1 MBytes163.30.44.9
    67672176/598.2 KBytes185.47.44.198   
    6969  5/562148.113.16.145
    http805108/7.0 MBytes210.231.212.90 25168/27.9 MBytes128.140.41.193
    8181  2/527148.113.16.145
    8888  2/218167.94.138.131
    8989  1/506148.113.16.145
    pop-3110  52/3.8 KBytes206.168.34.67
    1231238/384118.163.81.61 18/1.2 KBytes135.237.125.143
    netbios-ns13712/600163.30.44.7 12/600163.30.44.7
    143143  70/7.0 KBytes20.127.220.170
    snmp161  38648/10.4 MBytes185.247.137.12
    177177  1/764.62.156.94
    199199  2/44162.142.125.120
    389389  2/9164.62.197.149
    399399  1/14162.142.125.241
    427427  1/54123.58.205.67
    https44312458/3.3 MBytes45.88.138.20 3/2.7 KBytes52.165.80.115
    5005002/55247.254.155.21 10/2.9 KBytes167.94.138.149
    502502  2/1.2 KBytes74.235.184.174
    523523  1/2064.62.197.126
    587587  91/12.1 KBytes78.153.140.207
    623623  6/11664.62.156.56
    705705  1/60165.154.246.252
    873873  91/2.9 KBytes20.163.5.243
    993993  22/3.1 KBytes165.154.253.252

     

    TCP/UDP - Traffic on Other Ports

    Client PortServer Port

     

    TCP/UDP Recently Used Ports

    Client PortServer Port

     

    Recent Sessions: Network Delay

    Client ModeServer Mode
    Last TimeServiceLast Server ContactClient Delay [min/avg/max]
    Mon Jun 16 19:23:35 2025 HTTP210.231.212.90 0.01/0.02/0.06 ms
    Last TimeServiceLast Client ContactServer Delay [min/avg/max]
    Mon Jun 16 23:03:35 2025 HTTP128.140.41.193 0.01/0.02/0.13 ms
    Mon Jun 16 22:20:36 2025 Mail165.154.253.252 0.01/0.01/0.03 ms
    Mon Jun 16 21:52:00 2025 BitTorrent216.73.216.30 0.02/0.02/0.02 ms
    • Scenario: client <--> ntop <--> server
    • Client Delay: the network delay (computed as RTT/2) taken
      by a packet sent by the client to reach ntop
    • Server Delay: the network delay (computed as RTT/2) taken
      by a packet sent by the server to reach ntop
    • All times are majored during TCP 3-way handshake

     

    Active Sessions

    ProtoClientServerData Sent/RcvdActive SinceDurationInactiveClient/Server Nw DelayL7 Proto
    TCPchecker-nbg9.uptimerobot.com :55894 163.30.44.1  MultihomedNetwork Card VoIP DNS Mail (SMTP) HTTP Server Medium Risk :http605539Mon Jun 16 23:03:35 20250 sec46 sec113.23 ms0.02 msHTTP
    TCP216.73.216.30 :53434 163.30.44.1  MultihomedNetwork Card VoIP DNS Mail (SMTP) HTTP Server Medium Risk :3000631681Mon Jun 16 23:04:19 20251 sec1 sec90.72 ms0.02 ms 
    TCP216.73.216.30 :60408 163.30.44.1  MultihomedNetwork Card VoIP DNS Mail (SMTP) HTTP Server Medium Risk :30006801.4 KBytesMon Jun 16 23:03:27 20251 sec53 sec93.06 ms0.01 ms 

    The color of the host link indicates how recently the host was FIRST seen
      0 to 5 minutes     5 to 15 minutes     15 to 30 minutes     30 to 60 minutes     60+ minutes