Hello fellow coders, I have some questions regarding tcpdump timestamps. When exactly does tcpdump stamp the arriving and leaving packets? Given a scenario, where I was sending data out over an encrypted channel (say, ipsec), would timestamps detected over device ipsec0 correspond to the packets arrival after being decrypted, or do the stamps correlate to the eth0 timestamps. How about, if I was to use the ipsec0 timestamps compared to the eth0 timestamps in order to determine the encryption and decryption times for ipsec0. Would tcpdump be an accurate tool for this situation?
Thanx, Gabe Institute for Telecommunication Sciences / NTIA / DOC - This is the TCPDUMP workers list. It is archived at http://www.tcpdump.org/lists/workers/index.html To unsubscribe use mailto:[EMAIL PROTECTED]?body=unsubscribe
