Hi all-
I seem to remember a while ago a discussion of the MAC addresses
being all that tcpdump would return on a trace, and the need to see the IPs
instead. Well, just like in school, I should have paid more attention, I
am now in need of a good trace from tcpdump/ethereal and all I can get is a
layer 2 trace with MACs. How can I get the trace to return the IPs of the
two sides of the socket? I am running RH7.2, with tcpdump version 3.6.2-9
and libpcap version 0.6.2-9.
I can setup ethereal, and I get the same result, I also ave no entries in
the ARP cahce, arp -n, arp -e and others produce no results...
Please reply to my personal address as I get the digest of the
messages and want to get this working asap, and to reduce redundant traffic
on the list.
TIA,
Murray Butler
"I would point out that linked lists, mark-and-copy garbage
collection, and the Tab key are all patented too. Somebody
who always carefully checked first for software patents would
never write anything at all."
- Martin Pool, in the rsync FAQ