Linux Display Bandwidth Usage on Network Interface By Host Using iftop command

last updated in Categories Howto, Linux, Networking, RedHat/Fedora Linux

The iftop command listens to network traffic on a named network interface, or on the first interface, it can find which looks like an external interface if none is specified, and displays a table of current bandwidth usage by pairs of hosts. The iftop is a perfect tool for remote Linux server over an ssh based session.

iftop must be run by the root or the user who has sufficient permissions to monitor all network traffic on the network interface. See how to install iftop on CentOS/RHEL based server.



Type the command as per your Linux distro:

Install iftop on a Debian/Ubuntu Linux

Type the following apt-get command/apt command:
$ sudo apt-get install iftop

Install iftop on a CentOS/Fedora/RHEL/Scientific/Oracle Linux

Type the following yum command (first turn on EPEL repo):
$ sudo yum install iftop
Fedora Linux user type the following dnf command:
$ sudo dnf install iftop

Install iftop on Arch Linux

Type the following pacman command:
$ sudo pacman -S iftop

Install iftop on Alpine Linux

Type the following apk command:
# apk add iftop

Install iftop on Suse/OpenSuse Linux

Type the following zypper command:
# zypper install iftop

A note about installing iftop on Unix-like system

You can install iftop on Unix-like system such as FreeBSD, OpenBSD, MacOS and others too. This page only deals with Linux operating system. For example on FreeBSD one can install iftop using the following pkg command:
# pkg install iftop
On macOS Unix one can install it using the brew command:
$ brew install iftop


The syntax is:
iftop -i interface
iftop [options]

Type iftop command at the shell prompt to display traffic:
# iftop
Sample outputs:

Linux Display Bandwidth Usage on Network Interface using iftop command
iftop in action (click to enlarge image)

In this example, I am using eth0 interface:
# iftop -i eth0
Sample outputs:
Animated gif 01: iftop command in action
Animated gif 01: iftop command in action

However, iftop works best when you use filters. For example, if you want to find out how much bandwidth users are wasting or trying to figure out why the network is slow, run:
# iftop -f icmp
You can display or analyses packet flowing in and out of the network:
# iftop -F
Disable output for DNS traffic by using filter code such as:
# iftop -f 'not port domain'
iftop has many options read man page for further information see its man page – iftop(8)

See also:


And there you have it, you just learned how to display bandwidth usage on an interface by host. To get more info type the following man command or visit this page:
$ man iftop
$ iftop -h

iftop command options

-h display this message
-n don’t do hostname lookups
-N don’t convert port numbers to services
-p run in promiscuous mode (show traffic between other hosts on the same network segment)
-b don’t display a bar graph of traffic
-B Display bandwidth in bytes
-i interfacelisten on named interface
-f filter codeuse filter code to select packets to count (default: none, but only IP packets are counted)
-F net/maskshow traffic flows in/out of IPv4 network
-G net6/mask6show traffic flows in/out of IPv6 network
-ldisplay and count link-local IPv6 traffic (default: off)
-Pshow ports as well as hosts
-m limitsets the upper limit for the bandwidth scale
-c config filespecifies an alternative configuration file
-tuse text interface without ncurses
-o 2sSort by first column (2s traffic average)
-o 10sSort by second column (10s traffic average) [default]
-o 40sSort by third column (40s traffic average)
-o sourceSort by source address
-o destinationSort by destination address
-s numprint one single text output afer num seconds, then quit
-L numnumber of lines to print


Posted by: Vivek Gite

The author is the creator of nixCraft and a seasoned sysadmin, DevOps engineer, and a trainer for the Linux operating system/Unix shell scripting. Get the latest tutorials on SysAdmin, Linux/Unix and open source topics via RSS/XML feed or weekly email newsletter.

Start the discussion at

Historical Comment Archive

8 comment

  1. It is a very useful program. This commando shows I deal and the port of a single IP

    iftop -P -i any -F

  2. It’s also possible to apply filter when iftop is already running: just press “f” button and type filter you wish like:
    Net filter> host

  3. thanks, its great
    but i still have one question, can iftop change source ip (ex: at picture above) to hostname from each pc that connected?


  4. Something that works well via command line (especially for SSH) is iptraf. That lets you view stats with a wide variety of detail. Probably doesn’t work as well as this, but it works well enough 😉

  5. Thanks iftop is really useful tool, but how you to make the opposite of this “iftop -F” i mean to exclude local bandwidth?

    Have a question? Post it on our forum!