LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 09-21-2005, 08:59 AM   #1
jeffk42
Member
 
Registered: Mar 2005
Location: Orlando, FL USA
Distribution: Fedora Core 13 x86_64 / RHEL 5.3
Posts: 76

Rep: Reputation: 15
tcpdump / ethereal question


I'm not very comfortable with tcpdump yet, so I thought maybe I could get some help with this.

I'm writing a service that converts a machine-specific proprietary message format to XML, allowing clients of any type to receive the data and use it. The computer that serves the messages is not easily available to me, so I'd like to be able to test as much as possible without having to constantly go through the process of setting up an appointment, driving over there, etc.

So the last time I was there I hooked up my laptop and got myself a 2 MB ethereal dump. So here's the question: I've got this file, and I'd like to be able to somehow 'replay' the network traffic on my local network, basically creating a fake server that I can test my service with.

Ideally, I'd also like to filter out any traffic not originating from the server (I figure I can do this in ethereal and export the filtered results to a new file, right?)

Also, if it is possible to do this 'replay', only the actual packet data is transferred, correct? So if the raw dump I have is coming from 10.0.40.204 and I replay it on 192.168.0.14, it will show up as coming from 192.168.0.14?


Thanks in advance,
Jeff
 
Old 09-21-2005, 09:21 AM   #2
Gibsonist
Member
 
Registered: Mar 2004
Location: Meersburg (GER)
Distribution: Cygwin,RH 7.2 7.3, SuSe 6.4 8.2 9.1,TinyLinux, Debian Sarge, Knoppix 3.*, Knoppicilin, Knoppix STD
Posts: 191

Rep: Reputation: 30
Have you had a look at tcpreplay?
(here the official desc. taken from Debian)
Code:
Tcpreplay is aimed at testing the performance of a NIDS by replaying real
background network traffic in which to hide attacks. Tcpreplay allows you to
control the speed at which the traffic is replayed, and can replay arbitrary
tcpdump traces. Unlike programmatically-generated artificial traffic
which doesn't exercise the application/protocol inspection that a NIDS performs,
and doesn't reproduce the real-world anomalies that appear on production
networks (asymmetric routes, traffic bursts/lulls, fragmentation,
retransmissions, etc.), tcpreplay allows for exact replication
of real traffic seen on real networks.

https://sf.net/projects/tcpreplay/ http://tcpreplay.sourceforge.net/

Last edited by Gibsonist; 09-21-2005 at 09:22 AM.
 
Old 09-22-2005, 06:30 AM   #3
jeffk42
Member
 
Registered: Mar 2005
Location: Orlando, FL USA
Distribution: Fedora Core 13 x86_64 / RHEL 5.3
Posts: 76

Original Poster
Rep: Reputation: 15
Okay, I'll give that a shot. Thanks!
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Ethereal/TCPdump/Kismet, wireless sniffing scott4957 Linux - Software 1 10-17-2005 11:22 PM
Wireless sniffing with Ethereal/tcpdump/kismet scott4957 Linux - Wireless Networking 2 10-07-2005 01:13 PM
viewing tcpdump files in ethereal abirami Linux - Networking 2 09-28-2004 09:03 AM
tcpdump / ethereal on dialup disconnect TheVillageIdiot Linux - Software 1 09-20-2003 08:01 AM
re: some tcpdump/netstat/ethereal questions ezra_kim Linux - Networking 5 01-22-2003 05:38 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 07:55 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration