Re: Does tcpdump2xplot work?

2005-12-13 Thread Michael W. Oliver
On 2005-12-13T11:20:49-0500, Brian Reichert wrote:
> On Tue, Dec 13, 2005 at 11:00:57AM -0500, Brian Reichert wrote:
>> This may be pilot error, but for the life of me, I can't get
>> tcpdump2xplot to work as advertised.

>> Every lick of documentation I can find say to first create a netdump
>> libpcap file of TCP packets as such:
> 
> I misenterpreted the instructions; tcpdump2xplot does _not_ accept
> a capture file.
> 
> Other docs say I have to do this:
> 
>  tcpdump -tt -S -r tcpdump.out | tcpdump2xplot
> 
> But, I get the same error...

Check this out...

http://mail-index.netbsd.org/current-users/2004/11/30/0010.html

Does that help?

-- 
Mike Oliver
[see complete headers for contact information]


pgp60OAejm74J.pgp
Description: PGP signature


Re: Realtek RTL8169 on FreeBSD 5.4: no carrier.

2005-08-20 Thread Michael W. Oliver
On 2005-08-20T09:50:53+0400, Dmitry Mityugov wrote:
> On 8/10/05, Julien Gabel <[EMAIL PROTECTED]> wrote:
 Regrettably, i always encountered this problem.  I spoke about that
 since the middle of 2004, and didn't really receive feedback on this.
 I try a lot of things but none worked better than the other.

 To not forget about it, i filled a bug report on this particular
 problem, see PR kern/80005 for more details.

 The last thing i want to give another try is to upgrade to RELENG_6,
 since i currently follow the RELENG_5 branch.  But i am not *very*
 confident about that...

 Sorry not to have better answer to give you.

>>> IIRC, I have a RTL8169S-based D-Link gigabit network card at home and
>>> it works with FreeBSD just fine.

>> Yes, i know it simply works for a lot of users.  It doesn't mean that it
>> is the case for all users... i am of those.
> 
> Just realized that with ACPI disabled, this card does not work with
> FreeBSD 5.4 (at least in my machine), with ACPI enabled - it does.
> Hope this information will help somebody.

I have RTL8169S in my laptop, and have seen the same up/down/up/down
etc. behavior that is noted in PR 80005.  I am running 7-CURRENT about a
day old.  I switched from my custom kernel back to GENERIC and the
problem went away, so I started adding things from my custom config file
into GENERIC to see what finally broke it, and it turned out to be:

options ACPI_DEBUG

Just thought that I would mention it...


re0: Reserved 0x100 bytes for rid 0x10 type 4 at 0x1000
re0:  port 0x1000-0x10ff mem 
0xd0008800-0xd00088ff irq 19 at device 8.0 on pci0
miibus0:  on re0
rgephy0:  on miibus0
rgephy0:  10baseT, 10baseT-FDX, 100baseTX, 100baseTX-FDX, 1000baseTX, 
1000baseTX-FDX, auto
re0: bpf attached
re0: Ethernet address: 00:90:f5:32:35:9f
re0: [GIANT-LOCKED]


-- 
Mike Oliver
[see complete headers for contact information]


pgpYlryu57Wjo.pgp
Description: PGP signature


Re: Network monitoring

2004-11-23 Thread Michael W. Oliver
On 2004-11-23T17:21:48-0800, Simon Roberts wrote:
> I apologize that this probably isn't the most relevant
> list to ask this on. Suggestions for better lists will
> be welcome.
> 
> I'm trying to monitor traffice on a 100BaseT ethernet
> network link. I split the line, put a "hub" in and am
> trying to run tcpdump on a box off the side of the
> hub.
> 
> Unfortunately, it turns out the hub isn't a hub, it's
> a "switching hub" (what's not a switch about this? I
> don't get it). Consequently, all I see are arp
> packets, bootp packets, and the odd broadcast. I went
> to a local store to buy a hub, and guess what, they
> sold me another switching hub, so that has to be
> returned :(
> 
> So, the question is, can anyone tell me the
> manufacturer and product name of a real (dumb) hub? I
> could use 10baseT instead if necessary, I just need
> something cheap that is a simple repeater. Of course,
> nobody advertizes "our hub really is a totally dumb
> hub, not like those fancy switching hubs the
> competition sells" ;>
> 
> Any suggestions?

Yep, I have a suggestion or two.  First, you could try ettercap, which
is designed to do all sorts of neat things on switched networks.

If you want to really get into the guts of it, check this out:

http://www.snort.org/docs/tap/

A passive ethernet tap is a wonderful piece of gear to keep in your
toolbox, and unlike other pieces of wonderful gear, it won't cost you
thousands of dollars.

-- 
Michael W. Oliver
[see complete headers for contact information]



pgprzPKiaW0gH.pgp
Description: PGP signature


Re: Ugly Huge BSD Monster

2003-09-01 Thread Michael W. Oliver
+--- On Monday, September 01, 2003 10:42,
| Mario Freitas proclaimed:
|
| PS: Do you really need to compare windows "HUGE UGLY" and sluggish
| kernel with FreeBSD's?
| PS2:The monster has got a name, and it's not really a monster, is a
| daemon, it's "Chuck" ehehe
|

It isn't Chuck, though this myth persists on...

http://www.mckusick.com/beastie/index.html

-- 
++---------------+
| Michael W. Oliver, CCNP|  "The tree of liberty must be re- |
|   IPv6 & FreeBSD mark  | freshed from time to time with the|
| http://michael.gargantuan.com/ | blood of patriots and tyrants."   |
|ASpath-tree, Looking Glass, etc.|  - President Thomas Jefferson |
|+---+
|  gpg key - http://michael.gargantuan.com/gnupg/pubkey.asc  |
| perl -e 'print unpack("u", "7;6EC:&%E;\$!G87)G86YT=6%N+F-O;0H`");' |
++



pgp0.pgp
Description: signature