Create successful ePaper yourself
Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.
ash-2.03# snoop -v -c 1 -i <strong>fw</strong>moni<strong>to</strong>r.cap<br />
ETHER: ----- Ether Header -----<br />
ETHER:<br />
ETHER: Packet 1 arrived at 8:26:43.00<br />
ETHER: Packet size = 98 bytes<br />
ETHER: Destination = 69:31:65:74:68:30, (multicast)<br />
ETHER: Source = 0:0:0:0:0:0,<br />
ETHER: Ethertype = 0800 (IP)<br />
ETHER:<br />
IP: ----- IP Header -----<br />
IP:<br />
IP: Version = 4<br />
IP: Header length = 20 bytes<br />
IP: Type of service = 0x00<br />
IP: xxx. .... = 0 (precedence)<br />
IP: ...0 .... = normal delay<br />
IP: .... 0... = normal throughput<br />
IP: .... .0.. = normal reliability<br />
IP: Total length = 84 bytes<br />
IP: Identification = 47628<br />
IP: Flags = 0x4<br />
IP: .1.. .... = do not fragment<br />
IP: ..0. .... = last fragment<br />
IP: Fragment offset = 0 bytes<br />
IP: Time <strong>to</strong> live = 64 seconds/hops<br />
IP: Pro<strong>to</strong>col = 1 (ICMP)<br />
IP: Header checksum = 2679<br />
IP: Source address = 172.16.1.1, 172.16.1.1<br />
IP: Destination address = 172.16.1.2, 172.16.1.2<br />
IP: No options<br />
IP:<br />
ICMP: ----- ICMP Header -----<br />
ICMP:<br />
ICMP: Type = 8 (Echo request)<br />
ICMP: Code = 0 (ID: 51470 Sequence number: 256)<br />
ICMP: Checksum = 2be5<br />
ICMP:<br />
1 packets captured<br />
bash-2.03#<br />
Figure 50: Inspecting <strong>fw</strong> moni<strong>to</strong>r files with snoop – verbose output<br />
! Especially when working in verbose mode (-v) it is recommended <strong>to</strong> display only a few packets.<br />
! This paper does not cover advanced snoop usage including things like filtering, converting etc. You<br />
Use –c <strong>to</strong> limit the number of packets or <strong>use</strong> filter expressions. snoop filter expressions are not<br />
discussed in this paper. Refer <strong>to</strong> the snoop man page for further information.<br />
can find further information at The Secrets of Snoop.<br />
<strong>How</strong> <strong>to</strong> <strong>use</strong> <strong>fw</strong> moni<strong>to</strong>r Page 41 of 70<br />
Revision: 1.01