Suspicious high incoming traffic

Ask for help and report issues not specific to either the Mac OS X or GTK+ versions of Transmission
Post Reply
waltersamson
Posts: 1
Joined: Fri Feb 08, 2019 2:52 am

Suspicious high incoming traffic

Post by waltersamson »

Hello,
I noticed sometimes there is suspicious high incoming traffic from transmission (500KiB/s ~ 1000 KiB/s), but despite these incoming traffic, transmission shows zero peers connected and zero download/upload speed.

The traffic can be observed via ifstat and various other network monitoring tools.

Using 'nettop' it can be observed that trasmission is transferring traffic with various IP addresses, at the time of my writing one of the most noticable address is 114.245.146.234 which I cannot see what is paricular about it.

Is this normal or some kind of problem?

I'm running transmission 2.92(14714) on Debian 9.

Thanks!
killemov
Posts: 535
Joined: Sat Jul 31, 2010 5:04 pm

Re: Suspicious high incoming traffic

Post by killemov »

It could be spikes in metadata traffic. But if you experience this traffic for more than a fraction of a second at a time, so without any actual torrent-related traffic, you could be a target of an attack. Any particular ports or protocols involved?
Post Reply