tcpdump mailing list archives

Re: When using IPSec, tcpdump doesn't show outgoing packets


From: Michael Richardson <mcr () sandelman ca>
Date: Sun, 20 Feb 2011 11:35:48 -0500


"Kaushal" == Kaushal Shriyan <kaushalshriyan () gmail com> writes:
    Kaushal> Hi

    Kaushal> When i run the command tcpdump -i eth0 -s0 host IP and host
    Kaushal> IP , I just see only incoming traffic and not outgoing
    Kaushal> traffic. I am using IPSec Application.

    Kaushal> Please suggest/guide and let me know if you need any
    Kaushal> further information.

You'd have to tell us:
      a) what operating system (I'm guessing Linux).

      b) what IPsec stack you are using (many operating systems have
         multiple stacks)

      c) what the arrangement of tunnels and IPsec SAs you have, so that
         we'd know what packets you think you will see on "eth0"

Different IPsec stacks for Linux have very different properties about
how the packets flow, and what connections are available for tcpdump.

-- 
]       He who is tired of Weird Al is tired of life!           |  firewalls  [
]   Michael Richardson, Sandelman Software Works, Ottawa, ON    |net architect[
] mcr () sandelman ottawa on ca http://www.sandelman.ottawa.on.ca/ |device driver[
   Kyoto Plus: watch the video <http://www.youtube.com/watch?v=kzx1ycLXQSE>
                       then sign the petition. 
-
This is the tcpdump-workers list.
Visit https://cod.sandelman.ca/ to unsubscribe.


Current thread: