Snort mailing list archives
RE: capturing arp
From: Rich Adamson <radamson () routers com>
Date: Mon, 14 Apr 2003 08:20:09 -0600
That's not true; been using NAI Sniffer, Ethereal, etc, to view arp requests and responses for years. There could be some specific nic and OS that does not allow capturing, but haven't seen one in 20+ years of doing detailed protocol analysis. The TCP/IP protocol stack (including the ARP functions) have always been implemented in software (not hardware).
In all of my tests you can't capture arp packets because they are handled in hardware. If you use Nemesis and generate an ARP packet it isn't captured by Ethereal or Network General Sniffer.
------------------------------------------------------- This sf.net email is sponsored by:ThinkGeek Welcome to geek heaven. http://thinkgeek.com/sf _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- capturing arp Patrick Amirian (Apr 11)
- Re: capturing arp Chris Green (Apr 14)
- <Possible follow-ups>
- Re: capturing arp Sergio Aldo Casas (Apr 13)
- RE: capturing arp Spencer, Arthur (Apr 14)
- RE: capturing arp Rich Adamson (Apr 14)
- Re: capturing arp Jacques (Apr 14)
- Re: capturing arp Edin Dizdarevic (Apr 14)
- RE: capturing arp L. Christopher Luther (Apr 14)