Hello fellow coders,

I have some questions regarding tcpdump timestamps.  When exactly does tcpdump 
stamp the arriving and leaving packets?  Given a scenario, where I was 
sending data out over an encrypted channel (say, ipsec), would timestamps 
detected over device ipsec0 correspond to the packets arrival after being 
decrypted, or do the stamps correlate to the eth0 timestamps.  How about, if 
I was to use the ipsec0 timestamps compared to the eth0 timestamps in order 
to determine the encryption and decryption times for ipsec0.  Would tcpdump 
be an accurate tool for this situation?

Thanx,
Gabe
Institute for Telecommunication Sciences / NTIA / DOC

-
This is the TCPDUMP workers list. It is archived at
http://www.tcpdump.org/lists/workers/index.html
To unsubscribe use mailto:[EMAIL PROTECTED]?body=unsubscribe

Reply via email to