Skip to content

iftop

Display bandwidth usage on a network interface in real time.

Self-hostedNot yet verified
Report issueDemo online
MIT

Open the official app on www.ex-parrot.com

This tool is hosted by its maintainers. Click below to open www.ex-parrot.com in a new tab — it's their official demo.

Browse network tools →

What's next with iftop?

Choose how you want to get started.

Use it free

Open the official tool or demo — no account needed.

Free

Self-host it

Run the open-source version on your own infrastructure.

Open

What is iftop?

iftop is an open-source network monitoring tool that provides real-time visibility into bandwidth usage across a network interface. It functions similarly to the Unix 'top' command by displaying a dynamic table of active connections, showing data transfer rates between host pairs. Developed under the GNU General Public License v2, iftop is primarily used by network administrators and system engineers to diagnose performance issues, such as unexpectedly slow internet connections or unauthorized data transfers. By analyzing traffic patterns, it helps identify bandwidth hogs, troubleshoot connectivity problems, and ensure optimal network resource allocation. The tool relies on libpcap for packet capture and libcurses for terminal-based interface rendering, making it lightweight and suitable for Linux/Unix environments. Its ability to aggregate traffic by source and destination IP pairs makes it a critical tool for understanding network behavior without requiring complex configuration.

How it works

iftop is a command-line utility that monitors network traffic in real time, displaying bandwidth usage statistics for active connections. It operates by intercepting packets on a specified network interface and calculating throughput between pairs of hosts. The tool is designed to answer questions like 'why is my internet connection slow?' by revealing which processes or IP addresses are consuming the most bandwidth. Its output is particularly useful for identifying rogue devices, malware activity, or misconfigured applications. iftop provides real-time bandwidth usage metrics, including incoming and outgoing traffic rates, packet counts, and connection details. It supports filtering by IP address, port, and protocol, allowing users to focus on specific traffic patterns. For example, it can highlight a single host draining bandwidth or detect unusual traffic spikes from a particular subnet.

How to use it

  1. 1Install dependencies: Ensure libpcap and libcurses are installed via your package manager (e.g., `apt-get install libpcap-dev libncurses5-dev`). 2. Download the source code from the official repository or Freshmeat. 3. Compile using `./configure && make`. 4. Run with `sudo iftop -i eth0` to monitor traffic on the specified interface. Practical tips: Use `sudo` for root privileges, specify the correct network interface (e.g., `eth0` or `ens33`), and press `^C` to exit. For persistent monitoring, combine with tools like `screen` or `tmux`.

What it can do

  • bandwidth monitoring

Use cases

Assumptions and limitations

Assumptions

  • source: https://github.com/letoams/iftop
  • license: GPL-2.0 — free to use
  • privacy: Self-hosted — you control your data

Limitations

  • Requires root privileges to capture packets on most Linux distributions
  • Depends on libpcap, which may not be available or configured on all systems
  • Lacks advanced filtering options compared to tools like Wireshark or ntopng
  • Does not support GUI interfaces, limiting accessibility for non-technical users
  • Limited historical data retention; only shows real-time statistics

Understanding the result

Display bandwidth usage on a network interface in real time.

Tool details

  • Clearly flagged when a network request is needed.
  • No account, no sign-up, and no tracking of your content.
  • Powered by (MIT).
Built with
(letoams/iftop)
License
MIT
Runs locally
No — requires a network request
Verification
Not yet verified
Input
Query
Output
Text
Open-source source & license

Built with letoams/iftop. OpenToolVault provides the discovery and browser interface while crediting the original project maintainers.

Built with
License
MIT
View source on GitHub

Open-source project

OpenToolVault is an independent directory. We are not affiliated with or endorsed by this project.

References

Frequently asked

What is iftop and how does it differ from traditional network monitoring tools?

iftop is a terminal-based tool that provides real-time bandwidth usage statistics for active network connections, similar to how 'top' monitors CPU usage. Unlike tools like 'ifstat' or 'nload', it displays traffic between specific host pairs, making it easier to identify which processes or IP addresses are consuming bandwidth. It uses libpcap for packet capture and curses for interactive output, offering a balance between simplicity and detailed analysis.

How does iftop capture and analyze network traffic?

iftop uses libpcap (or its Windows equivalent, WinPcap/Npcap) to capture packets on a specified network interface. It then parses these packets to calculate bandwidth usage between source and destination IP addresses. The tool aggregates data in real time, displaying metrics like transfer rates, packet counts, and connection states. It prioritizes TCP traffic and provides estimates for UDP traffic based on packet size and count.

How can I monitor traffic between two specific hosts using iftop?

To monitor traffic between two hosts, run `iftop -i eth0 -F 192.168.1.100,192.168.1.200` to filter connections involving those IPs. Alternatively, use the 'Filter' field in the interface to apply a BPF filter like `host 192.168.1.100 and host 192.168.1.200`. This narrows the output to only traffic between the specified hosts, helping isolate specific communication patterns.

How does iftop compare to tools like ntopng or Wireshark?

iftop is simpler and faster for real-time bandwidth monitoring but lacks the advanced packet inspection and historical analysis features of Wireshark. ntopng offers more comprehensive network visibility with dashboards and flow analysis, while iftop focuses on immediate, lightweight traffic aggregation. For users needing both real-time stats and deep packet inspection, combining iftop with Wireshark or ntopng is often ideal.

What should I do if iftop fails to capture traffic on my interface?

First, verify the interface name using `ip a` or `ifconfig` to ensure you're specifying the correct device (e.g., `eth0`). Check for root privileges by using `sudo`. If the interface is not listed, ensure the interface is up and not blocked by firewall rules. Also, confirm that libpcap is correctly installed and that the kernel's packet capture capabilities are enabled.

Spotted something wrong with iftop, or want to maintain it? See how to help.