Snort mailing list archives
Re: tcpreplay
From: Edin Dizdarevic <edin.dizdarevic () interActive-Systems de>
Date: Tue, 06 May 2003 22:47:50 +0200
Hi, "record" the traffic between two hosts with tcpdump. Remember to use the "-s 1514", because tcpdump will only capture 68 bytes of a packet otherwise. Use a hub to connect the "client" and the "server". Then disconnect the one - (say server or client) and use tcpreplay to put the packets on the wire with one machine. Remember: you can't use the same packets twice, since the sequence numbers and other parameter won't fit and the machines will permanently send reset packets to each other. tcpreplay is using a special socket and will put the recorded packets (both the requests and the answers) on the wire no matter if someone is "listening" or not. You can even connect your stealth (do not forget the -arp switch) sensor and the replay machine with a crossover cable. In that case you may be able to replay the packets even faster than using a hub. MAC addresses does not really matter in that case. Regards, Edin Hanumantha R. Manchala wrote:
Hello all, I want to use tcpreplay to stress test snort. But I am unable to send the traffic to a destination MAC address given by the -I switch of tcpreplay. Does any one know how to send traffic to a particular MAC on the LAN? Or is it possible to send traffic to a specific IP? Thanks guys for ur help. good day! Thanks, Manchala.
-- Edin Dizdarevic ------------------------------------------------------- Enterprise Linux Forum Conference & Expo, June 4-6, 2003, Santa Clara The only event dedicated to issues related to Linux enterprise solutions www.enterpriselinuxforum.com _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- making a rule for passing data on a source network David Powell (May 06)
- tcpreplay Hanumantha R. Manchala (May 06)
- Re: tcpreplay Matt Kettler (May 06)
- Re: tcpreplay Edin Dizdarevic (May 06)
- RE: tcpreplay Matt Foster (May 07)
- Re: tcpreplay Edin Dizdarevic (May 06)
- Re: tcpreplay Matt Kettler (May 06)
- tcpreplay Hanumantha R. Manchala (May 06)