tcpdump mailing list archives
Re: question about -E parameter decrypting esp packets
From: Arien Vijn <arien.vijn () ams-ix net>
Date: Fri, 20 Feb 2009 10:38:45 +0100
On 20 Feb. 2009, at 10:29 AM, Torsten Krah wrote:
Am Freitag, 20. Februar 2009 02:35:04 schrieb Michael Richardson:First, are you capturing the entire packet?Hm what do you mean with "entire" packet? How do i know this?The command i have used i told - have i have to do something more to get theentire dump?
The snap length is set to 68 bytes by default on most OSes. That is enough to capture IP, ICMP, TCP and UDP. To capture the whole frame you need to run with: -s 0.
-- Arien - This is the tcpdump-workers list. Visit https://cod.sandelman.ca/ to unsubscribe.
Current thread:
- question about -E parameter decrypting esp packets Torsten Krah (Feb 19)
- Re: question about -E parameter decrypting esp packets Michael Richardson (Feb 19)
- Re: question about -E parameter decrypting esp packets Torsten Krah (Feb 20)
- Re: question about -E parameter decrypting esp packets Arien Vijn (Feb 20)
- Re: question about -E parameter decrypting esp packets Torsten Krah (Feb 20)
- Re: question about -E parameter decrypting esp packets Michael Richardson (Feb 20)
- Re: question about -E parameter decrypting esp packets Torsten Krah (Feb 20)
- Re: question about -E parameter decrypting esp packets Michael Richardson (Feb 19)
