On Fri, Jul 19, 2013 at 10:34 PM, WXR <1485739...@qq.com> wrote:
> Do you mean that if there is a large traffic flow on the nic,the tcpdump will 
> show 'dropped packets'?
>

Please read the tcpdump manpage for a better explanation, but
essentially, what comes into the nic is written to tcpdump's buffers,
and if tcpdump can't keep up, the kernel will overwrite or 'drop'
packets from the tcpdump buffer. What the nic drops (not iptables)
will never show up in tcpdump's buffer.

--David

Reply via email to