Snort mailing list archives

Re: [RGSPAM] Re: Semi-OT: Re-inject tcpdump captured traffic


From: Jordi Espasa Clofent <jordi.espasa () opengea org>
Date: Thu, 06 Dec 2007 21:30:42 +0100

The difference between your command and Marty's is that yours lacks
a '-n', so your host is trying like mad to resolve the IP addresses
passing on vr0.  If my speculation is correct, if you let that command
run long enough, you'll eventually see output.  I basically never run
tcpdump without a -n.

Completely correct reasoning.

-- 
Thanks
Jordi Espasa Clofent

-------------------------------------------------------------------------
SF.Net email is sponsored by: 
Check out the new SourceForge.net Marketplace.
It's the best place to buy or sell services for
just about anything Open Source.
http://sourceforge.net/services/buy/index.php
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: