tcpdump mailing list archives

Re: question about -E parameter decrypting esp packets


From: Arien Vijn <arien.vijn () ams-ix net>
Date: Fri, 20 Feb 2009 10:38:45 +0100


On 20 Feb. 2009, at 10:29 AM, Torsten Krah wrote:

Am Freitag, 20. Februar 2009 02:35:04 schrieb Michael Richardson:

 First, are you capturing the entire packet?

Hm what do you mean with "entire" packet? How do i know this?
The command i have used i told - have i have to do something more to get the
entire dump?

The snap length is set to 68 bytes by default on most OSes. That is enough to capture IP, ICMP, TCP and UDP. To capture the whole frame you need to run with: -s 0.

-- Arien



-
This is the tcpdump-workers list.
Visit https://cod.sandelman.ca/ to unsubscribe.


Current thread: