The "easiest" solution requires some learning. The netstat(1) command on
unix-based systems (including MacOS 10+) and possibly also ms-windows
can report the number of
BYTES passing through a network interface. On
most implementations the '-b' switch is used to show
BYTES and the '-I
ifacename' switch is used to define what interface you want to monitor.
Since this only gives you one count of the bytes, you also want to use
the "wait" switch, typically '-w #" so the command continuously runs
every "#" seconds.
$ netstat -bI tun0 -w 8
The reason to use a wait time of 8 seconds is the values you'll see will
be roughly equivalent to
BITS per second for the given 8 second
period (1 byte is 8 bits). Since most networking throughput is measured
in bits per second, this makes your life easy. Also, using a wait time
of 8 seconds avoids putting mostly pointless load on your system while
giving you a fairly solid average throughput value.
This method is very flexible. For example, if you're running one or more
VPN tunnels, you can monitor each tunnel individually, as well as the
underlying uplink connection. You just need to use the same command with
different '-I' interface names.
Additionally, unlike the inaccurate download speed values presented by
web browsers and similar applications, this is measuring the raw data
passing through the interface (i.e. with packet overhead), rather than
measuring how fast a file is being transfered (without packet overhead).
I just leave it running in a tmux window on my firewall so with just a
glance I can always see what the connection is doing.