Re: [tcpdump-workers] Tcpdump not showing packets while the TX counter increments.

2014-11-11 Thread Matthew Schumacher
Oh, sorry, that would have been helpful:

Slackware64-14.0

Linux 3.2.45 #2 SMP Fri May 31 20:14:55 CDT 2013 x86_64 Intel(R) Xeon(R)
CPU   X5550  @ 2.67GHz GenuineIntel GNU/Linux

glibc-2.15

I dug around in the kernel source looking for what exactly causes the
counter to increment, but it wasn't at all obvious what was going on.

Thanks for your help,
schu

On 11/10/2014 03:13 PM, Guy Harris wrote:
> 
> On Nov 10, 2014, at 2:17 PM, Matthew Schumacher  wrote:
> 
>> I have an unprovisioned ethernet interface showing some TX packets:
>>
>> # ifconfig -a eth1
>> eth1: flags=4163  mtu 1500
>>inet6 fe80::224:e8ff:fe80:9258  prefixlen 64  scopeid 0x20
>>ether 00:24:e8:80:92:58  txqueuelen 1000  (Ethernet)
>>RX packets 1334743  bytes 124150467 (118.3 MiB)
>>RX errors 0  dropped 128753314  overruns 0  frame 0
>>TX packets 81  bytes 6380 (6.2 KiB)
>>TX errors 0  dropped 0 overruns 0  carrier 0  collisions 0
>>device interrupt 48  memory 0xd800-d8012800
>>
>> But those aren't showing up with:
>>
>> # tcpdump -i eth1 -n -e -Q out
> 
> On what operating system is this?
> 
___
tcpdump-workers mailing list
tcpdump-workers@lists.tcpdump.org
https://lists.sandelman.ca/mailman/listinfo/tcpdump-workers


Re: [tcpdump-workers] Tcpdump not showing packets while the TX counter increments.

2014-11-11 Thread Guy Harris

On Nov 10, 2014, at 2:17 PM, Matthew Schumacher  wrote:

> I have an unprovisioned ethernet interface showing some TX packets:
> 
> # ifconfig -a eth1
> eth1: flags=4163  mtu 1500
>inet6 fe80::224:e8ff:fe80:9258  prefixlen 64  scopeid 0x20
>ether 00:24:e8:80:92:58  txqueuelen 1000  (Ethernet)
>RX packets 1334743  bytes 124150467 (118.3 MiB)
>RX errors 0  dropped 128753314  overruns 0  frame 0
>TX packets 81  bytes 6380 (6.2 KiB)
>TX errors 0  dropped 0 overruns 0  carrier 0  collisions 0
>device interrupt 48  memory 0xd800-d8012800
> 
> But those aren't showing up with:
> 
> # tcpdump -i eth1 -n -e -Q out

What happens with

tcpdump -i eth1 -n -e -p

i.e., not filtering only for outgoing packets, but also not running in 
promiscuous mode?  (Just to make sure that the direction filtering is done 
correctly on Linux.)
___
tcpdump-workers mailing list
tcpdump-workers@lists.tcpdump.org
https://lists.sandelman.ca/mailman/listinfo/tcpdump-workers