LQ Newbie
Registered: May 2006
Location: brunswick, maine
Distribution: slackware
Posts: 14
Original Poster
Rep:
|
from client interface:
# tcpdump -i eth0 'port 80'
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on eth0, link-type EN10MB (Ethernet), capture size 96 bytes
10:47:17.562902 IP 192.168.1.5.33392 > gw-in-f100.google.com.http: Flags [S], seq 1938104511, win 5840, options [mss 1460,sackOK,TS val 4952229 ecr 0,nop,wscale 6], length 0
10:47:17.623667 IP gw-in-f100.google.com.http > 192.168.1.5.33392: Flags [S.], seq 1415809077, ack 1938104512, win 5672, options [mss 1430,sackOK,TS val 4042873563 ecr 4952229,nop,wscale 6], length 0
10:47:17.623731 IP 192.168.1.5.33392 > gw-in-f100.google.com.http: Flags [.], ack 1, win 92, options [nop,nop,TS val 4952290 ecr 4042873563], length 0
10:47:17.626311 IP 192.168.1.5.33392 > gw-in-f100.google.com.http: Flags [.], ack 1, win 92, options [nop,nop,TS val 4952293 ecr 4042873563], length 524
10:47:17.626334 IP 192.168.1.5.33392 > gw-in-f100.google.com.http: Flags [P.], ack 1, win 92, options [nop,nop,TS val 4952293 ecr 4042873563], length 68
10:47:17.690812 IP gw-in-f100.google.com.http > 192.168.1.5.33392: Flags [.], ack 525, win 106, options [nop,nop,TS val 4042873630 ecr 4952293], length 0
10:47:17.690942 IP gw-in-f100.google.com.http > 192.168.1.5.33392: Flags [.], ack 593, win 106, options [nop,nop,TS val 4042873630 ecr 4952293], length 0
10:47:17.694781 IP gw-in-f100.google.com.http > 192.168.1.5.33392: Flags [P.], ack 593, win 106, options [nop,nop,TS val 4042873634 ecr 4952293], length 478
10:47:17.694825 IP 192.168.1.5.33392 > gw-in-f100.google.com.http: Flags [.], ack 479, win 108, options [nop,nop,TS val 4952361 ecr 4042873634], length 0
10:47:17.728750 IP 192.168.1.5.59493 > yo-in-f104.google.com.http: Flags [S], seq 1954726409, win 5840, options [mss 1460,sackOK,TS val 4952395 ecr 0,nop,wscale 6], length 0
10:47:17.782851 IP yo-in-f104.google.com.http > 192.168.1.5.59493: Flags [S.], seq 428526385, ack 1954726410, win 5672, options [mss 1430,sackOK,TS val 1178097641 ecr 4952395,nop,wscale 6], length 0
10:47:17.782931 IP 192.168.1.5.59493 > yo-in-f104.google.com.http: Flags [.], ack 1, win 92, options [nop,nop,TS val 4952449 ecr 1178097641], length 0
10:47:17.784289 IP 192.168.1.5.59493 > yo-in-f104.google.com.http: Flags [P.], ack 1, win 92, options [nop,nop,TS val 4952451 ecr 1178097641], length 596
10:47:17.784564 IP 192.168.1.5.59493 > yo-in-f104.google.com.http: Flags [.], ack 1, win 92, options [nop,nop,TS val 4952451 ecr 1178097641], length 524
10:47:17.784589 IP 192.168.1.5.59493 > yo-in-f104.google.com.http: Flags [P.], ack 1, win 92, options [nop,nop,TS val 4952451 ecr 1178097641], length 72
10:47:17.839500 IP yo-in-f104.google.com.http > 192.168.1.5.59493: Flags [.], ack 525, win 106, options [nop,nop,TS val 1178097698 ecr 4952451], length 0
10:47:17.839928 IP yo-in-f104.google.com.http > 192.168.1.5.59493: Flags [.], ack 597, win 106, options [nop,nop,TS val 1178097698 ecr 4952451], length 0
10:47:17.849555 IP yo-in-f104.google.com.http > 192.168.1.5.59493: Flags [P.], ack 597, win 106, options [nop,nop,TS val 1178097705 ecr 4952451], length 174
10:47:17.849607 IP 192.168.1.5.59493 > yo-in-f104.google.com.http: Flags [.], ack 1, win 92, options [nop,nop,TS val 4952516 ecr 1178097698,nop,nop,sack 1 {4255:4429}], length 0
from router internal interface:
# tcpdump -i eth0 'port 80'
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on eth0, link-type EN10MB (Ethernet), capture size 96 bytes
10:47:37.622051 IP 192.168.1.5.33392 > gw-in-f100.google.com.http: Flags [S], seq 1938104511, win 5840, options [mss 1460,sackOK,TS val 4952229 ecr 0,nop,wscale 6], length 0
10:47:37.682711 IP gw-in-f100.google.com.http > 192.168.1.5.33392: Flags [S.], seq 1415809077, ack 1938104512, win 5672, options [mss 1430,sackOK,TS val 4042873563 ecr 4952229,nop,wscale 6], length 0
10:47:37.682875 IP 192.168.1.5.33392 > gw-in-f100.google.com.http: Flags [.], ack 1, win 92, options [nop,nop,TS val 4952290 ecr 4042873563], length 0
10:47:37.685518 IP 192.168.1.5.33392 > gw-in-f100.google.com.http: Flags [.], ack 1, win 92, options [nop,nop,TS val 4952293 ecr 4042873563], length 524
10:47:37.685527 IP 192.168.1.5.33392 > gw-in-f100.google.com.http: Flags [P.], ack 1, win 92, options [nop,nop,TS val 4952293 ecr 4042873563], length 68
10:47:37.749854 IP gw-in-f100.google.com.http > 192.168.1.5.33392: Flags [.], ack 525, win 106, options [nop,nop,TS val 4042873630 ecr 4952293], length 0
10:47:37.749961 IP gw-in-f100.google.com.http > 192.168.1.5.33392: Flags [.], ack 593, win 106, options [nop,nop,TS val 4042873630 ecr 4952293], length 0
10:47:37.753784 IP gw-in-f100.google.com.http > 192.168.1.5.33392: Flags [P.], ack 593, win 106, options [nop,nop,TS val 4042873634 ecr 4952293], length 478
10:47:37.753972 IP 192.168.1.5.33392 > gw-in-f100.google.com.http: Flags [.], ack 479, win 108, options [nop,nop,TS val 4952361 ecr 4042873634], length 0
10:47:37.787908 IP 192.168.1.5.59493 > yo-in-f104.google.com.http: Flags [S], seq 1954726409, win 5840, options [mss 1460,sackOK,TS val 4952395 ecr 0,nop,wscale 6], length 0
10:47:37.841910 IP yo-in-f104.google.com.http > 192.168.1.5.59493: Flags [S.], seq 428526385, ack 1954726410, win 5672, options [mss 1430,sackOK,TS val 1178097641 ecr 4952395,nop,wscale 6], length 0
10:47:37.842091 IP 192.168.1.5.59493 > yo-in-f104.google.com.http: Flags [.], ack 1, win 92, options [nop,nop,TS val 4952449 ecr 1178097641], length 0
10:47:37.843515 IP 192.168.1.5.59493 > yo-in-f104.google.com.http: Flags [P.], ack 1, win 92, options [nop,nop,TS val 4952451 ecr 1178097641], length 596
10:47:37.843794 IP 192.168.1.5.59493 > yo-in-f104.google.com.http: Flags [.], ack 1, win 92, options [nop,nop,TS val 4952451 ecr 1178097641], length 524
10:47:37.843802 IP 192.168.1.5.59493 > yo-in-f104.google.com.http: Flags [P.], ack 1, win 92, options [nop,nop,TS val 4952451 ecr 1178097641], length 72
10:47:37.898565 IP yo-in-f104.google.com.http > 192.168.1.5.59493: Flags [.], ack 525, win 106, options [nop,nop,TS val 1178097698 ecr 4952451], length 0
10:47:37.898672 IP yo-in-f104.google.com.http > 192.168.1.5.59493: Flags [.], ack 597, win 106, options [nop,nop,TS val 1178097698 ecr 4952451], length 0
10:47:37.908604 IP yo-in-f104.google.com.http > 192.168.1.5.59493: Flags [P.], ack 597, win 106, options [nop,nop,TS val 1178097705 ecr 4952451], length 174
10:47:37.908775 IP 192.168.1.5.59493 > yo-in-f104.google.com.http: Flags [.], ack 1, win 92, options [nop,nop,TS val 4952516 ecr 1178097698,nop,nop,sack 1 {4255:4429}], length 0
from router public interface:
# tcpdump -i eth1 'port 80'
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on eth1, link-type EN10MB (Ethernet), capture size 96 bytes
10:47:37.622062 IP rrcs-208-105-173-89.nys.biz.rr.com.33392 > gw-in-f100.google.com.http: Flags [S], seq 1938104511, win 5840, options [mss 1460,sackOK,TS val 4952229 ecr 0,nop,wscale 6], length 0
10:47:37.682705 IP gw-in-f100.google.com.http > rrcs-208-105-173-89.nys.biz.rr.com.33392: Flags [S.], seq 1415809077, ack 1938104512, win 5672, options [mss 1430,sackOK,TS val 4042873563 ecr 4952229,nop,wscale 6], length 0
10:47:37.682881 IP rrcs-208-105-173-89.nys.biz.rr.com.33392 > gw-in-f100.google.com.http: Flags [.], ack 1, win 92, options [nop,nop,TS val 4952290 ecr 4042873563], length 0
10:47:37.685524 IP rrcs-208-105-173-89.nys.biz.rr.com.33392 > gw-in-f100.google.com.http: Flags [.], ack 1, win 92, options [nop,nop,TS val 4952293 ecr 4042873563], length 524
10:47:37.685530 IP rrcs-208-105-173-89.nys.biz.rr.com.33392 > gw-in-f100.google.com.http: Flags [P.], ack 1, win 92, options [nop,nop,TS val 4952293 ecr 4042873563], length 68
10:47:37.749849 IP gw-in-f100.google.com.http > rrcs-208-105-173-89.nys.biz.rr.com.33392: Flags [.], ack 525, win 106, options [nop,nop,TS val 4042873630 ecr 4952293], length 0
10:47:37.749957 IP gw-in-f100.google.com.http > rrcs-208-105-173-89.nys.biz.rr.com.33392: Flags [.], ack 593, win 106, options [nop,nop,TS val 4042873630 ecr 4952293], length 0
10:47:37.753779 IP gw-in-f100.google.com.http > rrcs-208-105-173-89.nys.biz.rr.com.33392: Flags [P.], ack 593, win 106, options [nop,nop,TS val 4042873634 ecr 4952293], length 478
10:47:37.753978 IP rrcs-208-105-173-89.nys.biz.rr.com.33392 > gw-in-f100.google.com.http: Flags [.], ack 479, win 108, options [nop,nop,TS val 4952361 ecr 4042873634], length 0
10:47:37.787921 IP rrcs-208-105-173-89.nys.biz.rr.com.59493 > yo-in-f104.google.com.http: Flags [S], seq 1954726409, win 5840, options [mss 1460,sackOK,TS val 4952395 ecr 0,nop,wscale 6], length 0
10:47:37.841901 IP yo-in-f104.google.com.http > rrcs-208-105-173-89.nys.biz.rr.com.59493: Flags [S.], seq 428526385, ack 1954726410, win 5672, options [mss 1430,sackOK,TS val 1178097641 ecr 4952395,nop,wscale 6], length 0
10:47:37.842097 IP rrcs-208-105-173-89.nys.biz.rr.com.59493 > yo-in-f104.google.com.http: Flags [.], ack 1, win 92, options [nop,nop,TS val 4952449 ecr 1178097641], length 0
10:47:37.843799 IP rrcs-208-105-173-89.nys.biz.rr.com.59493 > yo-in-f104.google.com.http: Flags [.], ack 1, win 92, options [nop,nop,TS val 4952451 ecr 1178097641], length 524
10:47:37.843806 IP rrcs-208-105-173-89.nys.biz.rr.com.59493 > yo-in-f104.google.com.http: Flags [P.], ack 1, win 92, options [nop,nop,TS val 4952451 ecr 1178097641], length 72
10:47:37.898560 IP yo-in-f104.google.com.http > rrcs-208-105-173-89.nys.biz.rr.com.59493: Flags [.], ack 525, win 106, options [nop,nop,TS val 1178097698 ecr 4952451], length 0
10:47:37.898668 IP yo-in-f104.google.com.http > rrcs-208-105-173-89.nys.biz.rr.com.59493: Flags [.], ack 597, win 106, options [nop,nop,TS val 1178097698 ecr 4952451], length 0
10:47:37.908598 IP yo-in-f104.google.com.http > rrcs-208-105-173-89.nys.biz.rr.com.59493: Flags [P.], ack 597, win 106, options [nop,nop,TS val 1178097705 ecr 4952451], length 174
10:47:37.908781 IP rrcs-208-105-173-89.nys.biz.rr.com.59493 > yo-in-f104.google.com.http: Flags [.], ack 1, win 92, options [nop,nop,TS val 4952516 ecr 1178097698,nop,nop,sack 1 {4255:4429}], length 0
10:48:37.767060 IP rrcs-208-105-173-89.nys.biz.rr.com.33392 > gw-in-f100.google.com.http: Flags [F.], seq 593, ack 479, win 108, options [nop,nop,TS val 5012369 ecr 4042873634], length 0
10:48:37.828403 IP gw-in-f100.google.com.http > rrcs-208-105-173-89.nys.biz.rr.com.33392: Flags [F.], seq 479, ack 594, win 106, options [nop,nop,TS val 4042933698 ecr 5012369], length 0
10:48:37.828580 IP rrcs-208-105-173-89.nys.biz.rr.com.33392 > gw-in-f100.google.com.http: Flags [.], ack 480, win 108, options [nop,nop,TS val 5012430 ecr 4042933698], length 0
|