Tcpdump on enc0 how to filter port 443

2019-05-05 Thread Mik J
Hello, Does anyone know how can I capture flows to port 443 on an enc0 interface # tcpdump -ni enc0tcpdump: listening on enc0, link-type ENC 12:29:52.626065 (authentic,confidential): SPI 0x63b38934: 192.168.2.1.18413 > 192.168.1.1.443: S 3266713948:3266713948(0) win 16384 (DF) (encap) But tcpd

Re: tcpdump on enc0

2006-07-05 Thread Chris Kuethe
On 7/5/06, Stephen Bosch <[EMAIL PROTECTED]> wrote: Does tcpdump work on enc0? Did you ifconfig enc0 up -- GDB has a 'break' feature; why doesn't it have 'fix' too?

Re: tcpdump on enc0

2006-07-05 Thread Paul de Weerd
On Wed, Jul 05, 2006 at 12:09:49PM -0600, Stephen Bosch wrote: | Otto Moerbeek wrote: | > On Wed, 5 Jul 2006, Stephen Bosch wrote: | > | >> Does tcpdump work on enc0? | > | > Are you really too lazy to read a manual page? | | And for the record -- since some people found that question beyond the |

Re: tcpdump on enc0

2006-07-05 Thread Will H. Backman
Otto Moerbeek wrote: On Wed, 5 Jul 2006, Stephen Bosch wrote: Otto Moerbeek wrote: On Wed, 5 Jul 2006, Stephen Bosch wrote: Does tcpdump work on enc0? Are you really too lazy to read a manual page? And for the record -- since some people found that question b

Re: tcpdump on enc0

2006-07-05 Thread Stephen Bosch
Matthew R. Dempsky wrote: > On Wed, Jul 05, 2006 at 11:30:54AM -0600, Stephen Bosch wrote: >> I am not seeing any traffic on enc0 when using tcpdump, that is why I >> asked. > > Are you sure IPsec is being used? Can you see IPsec-processed traffic > on the physical interface? Aye, I have other

Re: tcpdump on enc0

2006-07-05 Thread Otto Moerbeek
On Wed, 5 Jul 2006, Stephen Bosch wrote: > Otto Moerbeek wrote: > > On Wed, 5 Jul 2006, Stephen Bosch wrote: > > > >> Does tcpdump work on enc0? > > > > Are you really too lazy to read a manual page? > > And for the record -- since some people found that question beyond the > pale -- I have bee

Re: tcpdump on enc0

2006-07-05 Thread Matthew R. Dempsky
On Wed, Jul 05, 2006 at 11:30:54AM -0600, Stephen Bosch wrote: > I am not seeing any traffic on enc0 when using tcpdump, that is why I > asked. Are you sure IPsec is being used? Can you see IPsec-processed traffic on the physical interface?

Re: tcpdump on enc0

2006-07-05 Thread Hans-Joerg Hoexer
On Wed, Jul 05, 2006 at 11:10:43AM -0600, Stephen Bosch wrote: > Does tcpdump work on enc0? > > -Stephen- > yes: <[EMAIL PROTECTED]:1>$ sudo tcpdump -n -i enc0 Password: tcpdump: WARNING: enc0: no IPv4 address assigned tcpdump: listening on enc0, link-type ENC 19:32:49.036465 (authentic,confiden

Re: tcpdump on enc0

2006-07-05 Thread Jason Dixon
On Jul 5, 2006, at 1:31 PM, Stephen Bosch wrote: Marcus Glocker wrote: On Wed, Jul 05, 2006 at 11:10:43AM -0600, Stephen Bosch wrote: Does tcpdump work on enc0? -Stephen- $ man enc "The enc interface allows an administrator to see outgoing packets before they have been processed by ipse

Re: tcpdump on enc0

2006-07-05 Thread Stephen Bosch
Otto Moerbeek wrote: > On Wed, 5 Jul 2006, Stephen Bosch wrote: > >> Does tcpdump work on enc0? > > Are you really too lazy to read a manual page? And for the record -- since some people found that question beyond the pale -- I have been tcpdumping enc0 all morning and I am seeing no traffic, in

Re: tcpdump on enc0

2006-07-05 Thread Stephen Bosch
Otto Moerbeek wrote: > On Wed, 5 Jul 2006, Stephen Bosch wrote: > >> Does tcpdump work on enc0? > > Are you really too lazy to read a manual page? Please don't get me started. I have been working on this problem with precious little assistance from folks like you for over a week now, and I've re

Re: tcpdump on enc0

2006-07-05 Thread Otto Moerbeek
On Wed, 5 Jul 2006, Stephen Bosch wrote: > Does tcpdump work on enc0? Are you really too lazy to read a manual page? -Otto

Re: tcpdump on enc0

2006-07-05 Thread Stephen Bosch
Marcus Glocker wrote: > On Wed, Jul 05, 2006 at 11:10:43AM -0600, Stephen Bosch wrote: > >> Does tcpdump work on enc0? >> >> -Stephen- > > $ man enc > > "The enc interface allows an administrator to see outgoing packets before > they have been processed by ipsec(4), or incoming packets after the

Re: tcpdump on enc0

2006-07-05 Thread Marcus Glocker
On Wed, Jul 05, 2006 at 11:10:43AM -0600, Stephen Bosch wrote: > Does tcpdump work on enc0? > > -Stephen- $ man enc "The enc interface allows an administrator to see outgoing packets before they have been processed by ipsec(4), or incoming packets after they have been similarly processed, via t

Re: tcpdump on enc0

2006-07-05 Thread Roy Morris
tcpdump -entttv -i enc0 Stephen Bosch wrote: Does tcpdump work on enc0? -Stephen-

tcpdump on enc0

2006-07-05 Thread Stephen Bosch
Does tcpdump work on enc0? -Stephen-