07-03-2008
i would like to know about tcpdump
i would like to know about tcpdump
i would like to use tcpdump to get information about these
- Date
- time
- source hostname
- source mac address
- source ip address
- destination ip address
- see outbound only
then i use command like this
tcpdump -i le0 -n -q -tttt -e src net 192.168.5.0/24
it will show
2008-07-01 00:04:56.032108 00:0c:29:4c:6d:ff > 00:0c:29:b9:4a:e8, IPv4, length 62: 192.168.5.250.1248 > 64.233.189.99.80: tcp 0
2008-07-01 00:04:56.043136 00:0c:29:4c:6d:ff > 00:0c:29:b9:4a:e8, IPv4, length 60: 192.168.5.250.1247 > 208.109.162.150.80: tcp 0
2008-07-01 00:04:56.043186 00:0c:29:4c:6d:ff > 00:0c:29:b9:4a:e8, IPv4, length 396: 192.168.5.250.1247 > 208.109.162.150.80: tcp 342
2008-07-01 00:04:56.065106 00:0c:29:4c:6d:ff > 00:0c:29:b9:4a:e8, IPv4, length 60: 192.168.5.250.1247 > 208.109.162.150.80: tcp 0
2008-07-01 00:04:56.066702 00:0c:29:4c:6d:ff > 00:0c:29:b9:4a:e8, IPv4, length 60: 192.168.5.250.1247 > 208.109.162.150.80: tcp 0
2008-07-01 00:04:56.088741 00:0c:29:4c:6d:ff > 00:0c:29:b9:4a:e8, IPv4, length 60: 192.168.5.250.1248 > 64.233.189.99.80: tcp 0
ok. i've already know about
- Date
- time
- source mac address
- source ip address
- destination ip address
- see outbound only
but i haven't know "source hostname" yet.
How can i add option for tcpdump to know "source hostname"? ??????
9 More Discussions You Might Find Interesting
1. Programming
I have two net-card. one is 172.16.24.99(ENG) ,another is 172.16.25.99(ENG-B). Both masks is 255.255.255.0.
I will monitor data on the tcp port 8055 in ENG, How do I set option of tcpdump command (2 Replies)
Discussion started by: chenhao_no1
2 Replies
2. UNIX for Dummies Questions & Answers
does anybody know what the -d -dd and -ddd options are used for ?
thanks (2 Replies)
Discussion started by: ant04
2 Replies
3. IP Networking
Hi, I got the following question regarding tcpdump and I would appreciate your help/feedback:
--Scenario
I am instructed to capture the network traffic by getting the tcpdump data/files of our network for every hour.
--Problem
Some of the connections are still open when the capture is done... (1 Reply)
Discussion started by: jinsunnyvale
1 Replies
4. Cybersecurity
i would like to know about tcpdump
i would like to use tcpdump to get information about these
- Date
- time
- source hostname
- source mac address
- source ip address
- destination ip address
- see outbound only
then i use command like this
tcpdump -i le0 -n -q -tttt -e src net... (0 Replies)
Discussion started by: chamnanpol
0 Replies
5. Linux
Hi,
I want to capture TCPDUMP of traffic, I tried doing this but did not find success..can anyone plz correct it.
# tcpdump -s0 -vv -w /home/osuresh/test_tcp_dump host 10.12.10.22 && port 161
bash: tcpdump: command not found
# tcpdump -s0 -vv -w /home/osuresh/test_tcp_dump host... (5 Replies)
Discussion started by: sureshcisco
5 Replies
6. UNIX for Dummies Questions & Answers
Hi Everyone,
anyone face "tcpdump -i any" does not work? i mean if i use -i eth0, can capture eth0, or use -i eth1 also can. but then tcpdump -i any, seems cannot capture packets. :confused:
please advice, thanks (2 Replies)
Discussion started by: jimmy_y
2 Replies
7. Shell Programming and Scripting
I'm new to the Unix/Linux world. I have taken classes and played with a few simple scripts but never had a real world application. Here is my problem.
What I need to do is every 15min between 8am and 5pm, run
tcpdump -s 2000 -w flowroute-0000.pcap
where the "0000" is the current time.
... (4 Replies)
Discussion started by: Nasasdge
4 Replies
8. Debian
Hi.
Need Help with TcpDump
Trying to sniff associatio-request with tcpdump but when i run this tcpdump -i eth0 wlan subtype assoc-req i get this error
can anyone help me with this error ? Thanks alot !!:) (1 Reply)
Discussion started by: SoulZB
1 Replies
9. IP Networking
I've recently started learning to use TCPdump, and I find it pretty interesting. There's one thing I don't understand. When I tell it to capture packets on, say, the WiFi interface en1, it often captures packets sent or received by other hosts on the network. How can it do this? My... (3 Replies)
Discussion started by: Ultrix
3 Replies
LEARN ABOUT SUSE
ifndp-proxy
IFNDP-PROXY(5) Network configuration IFNDP-PROXY(5)
NAME
ifndp-proxy[-<interface name>] - IPv6 NDP and IPv4 ARP proxy entries
SYNOPSIS
/etc/sysconfig/network/ifndp-proxy
/etc/sysconfig/network/ifndp-proxy-<interface name>
DESCRIPTION
These files contain IPv6 NDP and IPv4 ARP proxy settings, that should be applied using the ip neigh add proxy command documented in the
ip(8) manual page that provides a common interface for IPv4 and IPv6.
The NDP/ARP proxy is required, e.g. when IP addresses from the same subnet have to be used on the interface of the host as well as on
interfaces behind a (tunnel) interface and using a bridge is not an option.
Don't forget to enable forwarding and the NDP/ARP proxy by setting
net.ipv6.conf.<all|default|interface name>.proxy_ndp = 1
net.ipv6.conf.<all|default|interface name>.forwarding = 1
and/or
net.ipv4.conf.<all|default|interface name>.proxy_arp = 1
net.ipv4.conf.<all|default|interface name>.forwarding = 1
or
net.ipv4.ip_forward = 1
either as global all setting in the /etc/sysctl.conf file or using the ifsysctl(5) files, that allow per-interface setup.
Forwarding can be also enabled in the /etc/sysconfig/sysctl file using the IP_FORWARD and IPV6_FORWARD variables.
The proxy entries are added and deleted using the if-{up|down}.d/ndp-proxy script, every time after an involved interface has been set
up or down.
SYNTAX
The format of the ifndp-proxy file is:
<address> <address interface> <proxy interface list>
The format of the ifndp-proxy-<address interface> file is same to above, but allows also to omit the address interface by using a "-" as
placeholder inside of the file, because it is already available in the file name:
<address> <address interface | -> <proxy interface list>
Lines beginning with # and blank lines are ignored.
Each line defines to add a proxy NDP/ARP entry with the address of or behind address interface to all interfaces in the proxy interface
list.
EXAMPLES
Let's assume, your machine is connected via eth0 to a switch with the networks 2001:db8:abba::/64 and 192.168.100.1/24 and is using the IP
address 1 itself. You'd like to use the addresses 11 and 12 e.g. for virtual machines behind the tap1 and tap2 interface, that is:
2001:db8:abba::1/64 -- local eth0 address
2001:db8:abba::11/64 -- address behind tap1
2001:db8:abba::12/64 -- address behind tap2
192.168.100.1/24 -- local eth0 address
192.168.100.11/24 -- address behind tap1
192.168.100.12/24 -- address behind tap2
then set up the following entries in the ifndp-proxy file:
2001:db8:abba::1 eth0 tap1 tap2
2001:db8:abba::11 tap1 eth0 tap2
2001:db8:abba::12 tap2 eth0 tap1
192.168.100.1 eth0 tap1 tap2
192.168.100.11 tap1 eth0 tap2
192.168.100.12 tap2 eth0 tap1
additionally to the routing entries in the routes or ifroute-<interface name> files.
BUGS
Please report bugs at <https://bugzilla.novell.com/>
AUTHOR
Marius Tomaschewski <mt@suse.de>
SEE ALSO
ifup(8) ifcfg(5) ifsysctl(8)
sysconfig December 2009 IFNDP-PROXY(5)