See log interface realy go to promisc mode on my linux box root@shake /root]# tcpdump -n -i eth0 eth0: Promiscuous mode enabled tcpdump: listening on eth0 in /var/log/messages Jun 3 08:51:10 shake -- root[472]: ROOT LOGIN ON tty2 Jun 3 09:42:07 shake sshd(pam_unix)[597]: session opened for user root by (uid=0) Jun 3 09:42:18 shake kernel: eth0: Promiscuous mode enabled. Jun 3 09:42:18 shake kernel: device eth0 entered promiscuous mode Jun 3 09:42:37 shake kernel: device eth0 left promiscuous mode what version of tcpdump you use (I use last 3.7.1 with libpcap 0.7.1) I can send you gz archive with compiled version
03.06.2002 9:39:02, Ramin Alidousti <[EMAIL PROTECTED]> wrote: >On Mon, Jun 03, 2002 at 09:33:38AM +0500, Alexey Talikov wrote: > >> Its issue of switch it create virtual chanell for packet >> if your ip 192.168.1.2 >> you can't see packets from 192.168.1.1 to 192.168.1.3 etc >> only broadcast and arp >> Solution: >> use hub or if exist monitoring port on switch > >That's what he's been saying (see below). Any other suggestions?? > >Ramin > >> >> 03.06.2002 4:52:56, Art Reisman <[EMAIL PROTECTED]> wrote: >> >> >It is my understanding with my network interface in >> >promisc mode, that I should be able to see all network >> >packets on my LAN with tcpdump (no parameters). >> > >> >For some reason I am not seeing IP traffic unless it >> >is destined for me or a broadcast. I replaced my HUB >> >with very old model to insure that it was not >> >switched. >> > >> >Do I need to restart my interface after setting >> >promisc mode? >> > >> >__________________________________________________ >> >Do You Yahoo!? >> >Yahoo! - Official partner of 2002 FIFA World Cup >> >http://fifaworldcup.yahoo.com >> > >> >> ----------------------------------- >> mailto:[EMAIL PROTECTED] >> BR >> Alexey Talikov >> FORTEK >> ----------------------------------- >> >> > ----------------------------------- mailto:[EMAIL PROTECTED] BR Alexey Talikov FORTEK -----------------------------------
