LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 05-29-2007, 03:25 AM   #1
newbie_adm
Member
 
Registered: Jun 2006
Posts: 40

Rep: Reputation: 15
Interpreting and Understanding tcpdump file


Hi,
I am new to networking, and I was ask to do a tcpdump on a certain source and destination. I have executed this command successfully. The output file processed in ethereal software so I could get the full details. But since I'm new with this one. I don't undertand that much.
specially the line (Packet size limited during capture). THis appearred on both source and destination.Below are sample tcpdump ooutput file. Please help me, I'm kinda stuck on this one. Thanks


Source DST Protocol Info
205.135.86.25 69.180.85.26 SIP Request: INVITE sip:0118521236547@69.180.85.26[Packet size limited during capture]
205.135.86.25 69.180.85.26 SIP Request: OPTIONS sip:69.180.85.26[Packet size limited during capture]
69.180.85.26 205.135.86.25 SIP Status: 100 Trying[Packet size limited during capture]
69.180.85.26 205.135.86.25 SIP Status: 200 Ok [Packet size limited during capture]
69.180.85.26 205.135.86.25 SIP Status: 183 Ok [Packet size limited during capture]
69.180.85.26 205.135.86.25 SIP Status: 200 OK[Packet size limited during capture]
205.135.86.25 69.180.85.26 SIP Request: ACK sip: 0118521236547@69.180.85.26[Packet size limited during capture]

Thank you very much

Best Regards,
newbie_adm
 
Old 05-29-2007, 03:32 AM   #2
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
well what do you want to know? you have the source IP followed by the destination IP. then it's the protocol, SIP, then the SIP specific details, status code etc... not much else to tell you to be honest. if you check the wireshark wiki you can get sample captures of all sorts of traffic, like SIP including deliberate errors etc... at the SIP level though, it's up to you to understand the protocols in place, based on reference books etc... wireshark as a program is very useful to scrape out extra details from a tcpdump file. note of course that those packets are sizse limited, so only of a certian use, add "-s0" to the tcpdump command line to capture 100% of the data.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Interpreting an ancient Macintosh file? Tralce General 8 12-12-2006 03:40 PM
tcpdump file vkmgeek Linux - Networking 1 08-18-2006 01:53 AM
Need help interpreting tcpdump output line wrw3 Linux - Networking 0 10-29-2005 07:47 PM
retransmiting tcpdump capture file? JWT2 Linux - Networking 9 10-09-2005 08:27 AM
tcpdump -w command doesn't write to file andykerouac Linux - Networking 2 03-03-2004 07:10 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 02:55 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration