Re: I would like to tcpdump and get all the packets...

From: Petri Helenius (pete_at_he.iki.fi)
Date: 09/18/03

  • Next message: Josef Karthauser: "Traffic analysis ports?"
    Date: Thu, 18 Sep 2003 09:14:46 +0300
    To: Edwin Groothuis <edwin@mavetju.org>
    
    

    Edwin Groothuis wrote:

    >On Wed, Sep 17, 2003 at 06:31:03PM -0700, Josh Brooks wrote:
    >
    >
    >>Whenever I run:
    >>
    >>tcpdump -vvv
    >>
    >>when I am finished, I am surprised to see:
    >>
    >>27441 packets received by filter
    >>7866 packets dropped by kernel
    >>
    >>
    >
    >That's because the buffer of captures-but-not-yet-processed packets
    >in tcpdump was filled up. In other words, your system is to slow
    >to process the amount of traffic going through your machine.
    >
    >
    >
    Sure, but because the bug in pcap-bpf.c there is no way to set the
    buffer above 32768
    without recompiling the library after applying the patch.

    This bug should be fixed in the FreeBSD copy of libpcap because tcpdump
    folks seem
    to be quite dormant.

    Pete

    _______________________________________________
    freebsd-net@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-net
    To unsubscribe, send any mail to "freebsd-net-unsubscribe@freebsd.org"


  • Next message: Josef Karthauser: "Traffic analysis ports?"

    Relevant Pages

    • Re: if_em goes mum
      ... so the entering of power-saving would be the bug. ... Tcpdump says that packets are still received however, ...
      (freebsd-current)
    • Re: odd tcpdump output w/ 6.0-BETA2 ...
      ... I get useless output from tcpdump (no ... >>header or protocol decode) but only when I specify a filter on the ... Could someone with a stock BETA2 kernel try a tcpdump with a simple ...
      (freebsd-net)
    • Re: I would like to tcpdump and get all the packets...
      ... > I just noticed that Bill committed fix to this bug back in February. ... Shurely you mean tcpdump 3.7.2, which is already imported (by fenner, with ... To unsubscribe, ...
      (freebsd-net)
    • Re: Incorrect TCP checksum when printing to IO::Socket object
      ... If your server is Linux kernel 2.6,then it has a already known bug about the uncorrect checksum. ... If it's not 2.6 kernel,then you maybe want to use tcpdump for a try.I give most trust to tcpdump than other sniffers. ... I get incorrect checksums without the \n as well. ...
      (perl.beginners)
    • Re: [Full-Disclosure] SUSE Security Announcement: tcpdump (SuSE-SA:2004:002)
      ... > There is a bug in the tcpdump code responsible for handling ISAKMP ... Full-Disclosure - We believe in it. ... Charter: http://lists.netsys.com/full-disclosure-charter.html ...
      (Full-Disclosure)