15.07.2012 Views

How to use fw monitor

How to use fw monitor

How to use fw monitor

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

ash-2.03# snoop -v -c 1 -i <strong>fw</strong>moni<strong>to</strong>r.cap<br />

ETHER: ----- Ether Header -----<br />

ETHER:<br />

ETHER: Packet 1 arrived at 8:26:43.00<br />

ETHER: Packet size = 98 bytes<br />

ETHER: Destination = 69:31:65:74:68:30, (multicast)<br />

ETHER: Source = 0:0:0:0:0:0,<br />

ETHER: Ethertype = 0800 (IP)<br />

ETHER:<br />

IP: ----- IP Header -----<br />

IP:<br />

IP: Version = 4<br />

IP: Header length = 20 bytes<br />

IP: Type of service = 0x00<br />

IP: xxx. .... = 0 (precedence)<br />

IP: ...0 .... = normal delay<br />

IP: .... 0... = normal throughput<br />

IP: .... .0.. = normal reliability<br />

IP: Total length = 84 bytes<br />

IP: Identification = 47628<br />

IP: Flags = 0x4<br />

IP: .1.. .... = do not fragment<br />

IP: ..0. .... = last fragment<br />

IP: Fragment offset = 0 bytes<br />

IP: Time <strong>to</strong> live = 64 seconds/hops<br />

IP: Pro<strong>to</strong>col = 1 (ICMP)<br />

IP: Header checksum = 2679<br />

IP: Source address = 172.16.1.1, 172.16.1.1<br />

IP: Destination address = 172.16.1.2, 172.16.1.2<br />

IP: No options<br />

IP:<br />

ICMP: ----- ICMP Header -----<br />

ICMP:<br />

ICMP: Type = 8 (Echo request)<br />

ICMP: Code = 0 (ID: 51470 Sequence number: 256)<br />

ICMP: Checksum = 2be5<br />

ICMP:<br />

1 packets captured<br />

bash-2.03#<br />

Figure 50: Inspecting <strong>fw</strong> moni<strong>to</strong>r files with snoop – verbose output<br />

! Especially when working in verbose mode (-v) it is recommended <strong>to</strong> display only a few packets.<br />

! This paper does not cover advanced snoop usage including things like filtering, converting etc. You<br />

Use –c <strong>to</strong> limit the number of packets or <strong>use</strong> filter expressions. snoop filter expressions are not<br />

discussed in this paper. Refer <strong>to</strong> the snoop man page for further information.<br />

can find further information at The Secrets of Snoop.<br />

<strong>How</strong> <strong>to</strong> <strong>use</strong> <strong>fw</strong> moni<strong>to</strong>r Page 41 of 70<br />

Revision: 1.01

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!