tcpdump mailing list archives

Re: [WinPcap-users] No ARP traffic


From: "Gisle Vanem" <giva () bgnett no>
Date: Mon, 28 Apr 2003 12:08:27 +0200

"Guy Harris" <guy () alum mit edu> said:

I tried it on Windows 2000, with both WinPcap 2.3 and 3.0, and it
worked, with the filter "ip or arp" in Ethereal and "(ip or arp) and not
port 6000" in WinDump 3.8 alpha (which is what

Sorry, false alarm folks. I forgot I had the Sygate Personal Firewall
running. Turning that off everything works:

windump -tnve ip or arp
windump.exe: listening on \Device\NPF_{93380695-0E31-456C-9EB0-8802E111C09D}
00:01:80:0c:70:b2 ff:ff:ff:ff:ff:ff 0806 42: arp who-has 10.0.0.1 tell 10.0.0.6
00:00:c5:92:36:c4 00:01:80:0c:70:b2 0806 60: arp reply 10.0.0.1 is-at 00:00:c5:92:36:c4
00:01:80:0c:70:b2 00:00:c5:92:36:c4 0800 74: (tos 0x0, ttl 64, length: 60) 10.0.0.6 > 10.0.0.1: icmp 40: echo request 
seq 11776
00:00:c5:92:36:c4 00:01:80:0c:70:b2 0800 74: (tos 0x0, ttl 255, length: 60) 10.0.0.1 > 10.0.0.6: icmp 40: echo reply 
seq 11776

--gv

-
This is the TCPDUMP workers list. It is archived at
http://www.tcpdump.org/lists/workers/index.html
To unsubscribe use mailto:tcpdump-workers-request () tcpdump org?body=unsubscribe


Current thread: