When interface is specified I can get lot of data, but nothing readable related 
to the host  192.168.1.22.
I could verify that data is coming from 192.168.1.22 through the interface by 
looking the opened sessions and sql sentences
executing on my Oracle data base running on the server where I hit the tcpdum 
command.



Hugo




             John Summerfied <[EMAIL PROTECTED]>
             Sent by: Linux on 390 Port
             <[email protected]>                                          
                                                                   To
                                                                     
[email protected]
                                                                                
                                                                   cc
             11/03/2005 03:01 PM
                                                                                
                                                              Subject
                                                                     Re: tcpdump
                            Please respond to
               Linux on 390 Port <[email protected]>








Hugo Rivera wrote:
> Hello list,
>
> I'm trying to monitoring the traffic on my network and record packets that 
> meet certain criteria using the command:
>
> tcpdump host 192.168.1.22
>
> Then I received the messages:
>
>  tcpdump: listening on eth0
>
> Though data is going through etho interface nothing else is shown. I'm 
> missing something???....only error messages are shown???
> Thanks in advance.

Just to clarify, you're monitoring on one of the hosts involved in the
traffic?

I don't think this is your problem, but I like to specify the interface.
Does this do differently?

tcpdump -i eth0


--

Cheers
John

-- spambait
[EMAIL PROTECTED]  [EMAIL PROTECTED]
Tourist pics http://portgeographe.environmentaldisasters.cds.merseine.nu/

do not reply off-list

----------------------------------------------------------------------
For LINUX-390 subscribe / signoff / archive access instructions,
send email to [EMAIL PROTECTED] with the message: INFO LINUX-390 or visit
http://www.marist.edu/htbin/wlvindex?LINUX-390

----------------------------------------------------------------------
For LINUX-390 subscribe / signoff / archive access instructions,
send email to [EMAIL PROTECTED] with the message: INFO LINUX-390 or visit
http://www.marist.edu/htbin/wlvindex?LINUX-390

Reply via email to