Re: Capturing Raw packets



bobrics wrote:
Hello,

I have written a code to send raw data using PF_PACKET to an interface.
Before, on FC4, I was able to see the packets sent using tcpdump.
However, using the same code on Ubuntu , I5.10 cannot capture the
message send. Maybe I have to enable some special options in TCPDUMP?
I have tried on both, wireless and regular ethernet activated
interfaces, but still getting the same results. Please let me know what
do you think.
For what it's worth, use the pcap library for packet capturing,
it's quite portable and easy to use. (and also what tcpdump uses)
.



Relevant Pages

  • Re: Packet capturing, iptables and eth0 vs. dummy0
    ... > tcpdump gets all packets from interface eth0 as seen in the bus, ... > filter, I cannot connect, but no output ... > comes from tcpdump, which is exactly what I expected in the case ... Is normal that tcpdump shows packets before they ...
    (Linux-Kernel)
  • Re: bpf does not see packets forwarded with ipfw fwd
    ... tcpdump does not show locally originated outgoing IP ... packets that were processed by 'ipfw fwd' rule. ... connected with ethernet intefaces. ... out trough mentioned another interface. ...
    (freebsd-net)
  • Packet capturing, iptables and eth0 vs. dummy0
    ... tcpdump gets all packets from interface eth0 as seen in the bus, ... I'm listening, with tcpdump, to all packets in eth0. ... connect (without the filter I can do it normally), ...
    (Linux-Kernel)
  • Re: Policy-based routing for packets originating from local machine (reinject packets back into
    ... have set up nat and balanced routing for machines ... work with packets originating from the router itself. ... rules don't work as it seems local packets don't have any 'in' interface ... ('tcpdump -ni ngeth0' on other terminal for great justice) ...
    (freebsd-net)
  • Terminal Server Setup
    ... description GRE Tunnel Source Interface ... input packets with dribble condition detected ... output buffer failures, ... Serial1/0 is up, line protocol is up ...
    (comp.dcom.sys.cisco)