tcpdump mailing list archives

capturing return packets on bridges


From: Maarten Vanraes <maarten () ba be>
Date: Tue, 22 Feb 2011 15:41:25 +0100

Hi,

I couldn't find a FAQ relating to this, allthough i'm pretty sure this has been 
asked before:

the br0 bridge has an IP address and is requesting a webpage somewhere 
directly on that network.

when running "tcpdump -n -i br0", i see the tcp packet going out, but not 
returning. while the wget effectively works perfectly, so there has to be a 
return packet...

i read somewhere this could be due to source MAC address being 
00:00:00:00:00:00 .

my question is, can tcpdump actually show this, or is this related to pcap or 
the kernel? or is there a way i can let tcpdump show these packets?

Kind Regards,

Maarten
-
This is the tcpdump-workers list.
Visit https://cod.sandelman.ca/ to unsubscribe.


Current thread: