tcpdump mailing list archives

Re: ipv6 DAD packets?


From: Eloy Paris <peloy () chapus net>
Date: Thu, 03 Mar 2011 17:23:33 -0500

On 03/03/2011 03:52 PM, Jeff Sadowski wrote:

On Thu, Mar 3, 2011 at 1:31 PM, Eloy Paris<peloy () chapus net>  wrote:
On 03/03/2011 02:48 PM, Jeff Sadowski wrote:

[...]

I tried "tcpdump ip6 and icmp" but it says im blocking all. How would
I do what I am trying to do?
I can't quite figure out tcpdump syntax.

"tcpdump icmp6", per pcap-filter(7), does not do what you need?

with -vv it shows the mac but Is there a way to put the full packet
all on one line that I can parse the output easier

If the simple decoder that tcpdump has for the particular type of packets you need to decode does not provide enough detail then you probably need to look at tshark instead. With tshark you can also get packet details in a markup language, which may make parsing easier.

Cheers,

Eloy Paris.-
-
This is the tcpdump-workers list.
Visit https://cod.sandelman.ca/ to unsubscribe.


Current thread: