On 21/09/10 16:23, Jeff Wojciechowski wrote:

boot up (so before the client has an ip from dhcp - isn't the dhcp
transaction all arp?)

No. It's UDP packets on ports 67 and 68.

It uses source/dest addresses of 0.0.0.0 and 255.255.255.255, but it's still plain IP packets, so embedded packet capture should work.
_______________________________________________
cisco-nsp mailing list  [email protected]
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/

Reply via email to