Hi,
LB> Can you send tcpdumps of the packet leaving on eth1 including ethernet
LB> headers? Something like
LB> tcpdump -i eth1 -R -e -x -v -n
[root@Urtho-1 /root]# tcpdump -V
tcpdump version 3.4
libpcap version 0.4
[root@Urtho-1 /root]# tcpdump -v -e -x -n -i eth1 -R not tcp and not udp and not arp
Kernel filter, protocol ALL, TURBO mode (575 frames), raw packet socket
tcpdump: listening on eth1
20:16:02.494067 > 20:a4:90:c1:0:0 0:0:20:d0:76:c1 0000 1514: sap 20 > sap 45 I
(s=2,r=110,P) len=1496
fee9 2000 fc01 a95f d44c 2004 d44c 281a
0800 0e67 3e21 0000 1c03 9d3b 2c97 0b00
0809 0a0b 0c0d 0e0f 1011 1213 1415 1617
1819 1a1b 1c1d 1e1f 2021 2223 2425 2627
2829 2a2b 2c2d 2e2f 3031 3233 3435 3637
3839 3a3b 3c3d 3e3f 4041 4243 4445 4647
4849 4a4b 4c4d 4e4f 5051 5253 5455 5657
5859 5a5b 5c5d 5e5f 6061 6263 6465 6667
6869 6a6b 6c6d 6e6f 7071 7273
4520 05dc fee9 2000 fc01 a95f d44c 2004
d44c 281a 0800 0e67 3e21 0000 1c03 9d3b
2c97 0b00 0809 0a0b 0c0d 0e0f 1011 1213
1415 1617 1819 1a1b 1c1d 1e1f 2021 2223
2425 2627 2829 2a2b 2c2d 2e2f 3031 3233
3435 3637 3839 3a3b 3c3d 3e3f 4041 4243
4445 4647 4849 4a4b 4c4d 4e4f 5051 5253
5455 5657 5859 5a5b 5c5d 5e5f 6061 6263
6465 6667 6869 6a6b 6c6d 6e6f 7071 7273
20:16:02.494102 > 0:c0:df:6:65:4c 0:10:5a:b:7e:d1 ip 62: 212.76.32.4 > 212.76.40.26:
(frag 65257:28@1480) [tos 0x20] (ttl 252)
4520 0030 fee9 00b9 fc01 ce52 d44c 2004
d44c 281a c0c1 c2c3 c4c5 c6c7 c8c9 cacb
cccd cecf d0d1 d2d3 d4d5 d6d7 d8d9 dadb
or another time:
[root@Urtho-1 /root]# tcpdump -v -e -x -n -i eth1 -R not tcp and not udp and not arp
Kernel filter, protocol ALL, TURBO mode (575 frames), raw packet socket
tcpdump: listening on eth1
21:03:48.628088 > 55:55:0:0:c:b1 0:0:20:0:0:0 0c08 1514:
4520 05dc 3f72 2000 fc01 68d7 d44c 2004
d44c 281a 0800 9f90 c665 0000 4f0e 9d3b
e91d 0200 0809 0a0b 0c0d 0e0f 1011 1213
1415 1617 1819 1a1b 1c1d 1e1f 2021 2223
2425 2627 2829 2a2b 2c2d 2e2f 3031 3233
3435 3637 3839 3a3b 3c3d 3e3f 4041 4243
4445 4647 4849 4a4b 4c4d 4e4f 5051 5253
5455 5657 5859 5a5b 5c5d 5e5f 6061 6263
6465 6667 6869 6a6b 6c6d 6e6f 7071 7273
21:03:48.628124 > 34:80:4:8:34:80 0:0:34:0:0:0 0408 62: sap 20 > sap 45 I (s=0,r=24,P)
len=44
3f72 00b9 fc01 8dca d44c 2004 d44c 281a
c0c1 c2c3 c4c5 c6c7 c8c9 cacb cccd cecf
d0d1 d2d3 d4d5 d6d7 d8d9 dadb
4520 0030 3f72 00b9 fc01 8dca d44c 2004
d44c 281a c0c1 c2c3 c4c5 c6c7 c8c9 cacb
cccd cecf d0d1 d2d3 d4d5 d6d7 d8d9 dadb
[root@Urtho-1 /root]# tcpdump -v -e -x -n -i eth0 -R not tcp and not udp and not arp
Kernel filter, protocol ALL, TURBO mode (575 frames), raw packet socket
tcpdump: listening on eth0
20:17:26.484847 P 0:5:5f:ea:2c:70 0:10:5a:b:7e:d1 ip 62: 212.76.32.4 > 212.76.40.26:
(frag 65258:28@1480) (DF) [tos 0x20] (ttl 252)
4520 0030 feea 40b9 fc01 8e51 d44c 2004
d44c 281a c0c1 c2c3 c4c5 c6c7 c8c9 cacb
cccd cecf d0d1 d2d3 d4d5 d6d7 d8d9 dadb
20:17:26.487070 P 0:5:5f:ea:2c:70 0:10:5a:b:7e:d1 ip 1514: 212.76.32.4 > 212.76.40.26:
icmp: echo request (frag 65258:1480@0+) (DF) [tos 0x20] (ttl 252)
4520 05dc feea 6000 fc01 695e d44c 2004
d44c 281a 0800 8d5c e924 0000 7003 9d3b
ae9d 0b00 0809 0a0b 0c0d 0e0f 1011 1213
1415 1617 1819 1a1b 1c1d 1e1f 2021 2223
2425 2627 2829 2a2b 2c2d 2e2f 3031 3233
3435 3637 3839 3a3b 3c3d 3e3f 4041 4243
4445 4647 4849 4a4b 4c4d 4e4f 5051 5253
5455 5657 5859 5a5b 5c5d 5e5f 6061 6263
6465 6667 6869 6a6b 6c6d 6e6f 7071 7273
Urtho,
_______________________________________________
Bridge mailing list
[EMAIL PROTECTED]
http://www.math.leidenuniv.nl/mailman/listinfo/bridge