Advertisement
Guest User

Untitled

a guest
Sep 22nd, 2017
67
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 16.33 KB | None | 0 0
  1. fw-bib:~# tcpdump -vvvnettti eth5 icmp
  2. tcpdump: listening on eth5, link-type EN10MB (Ethernet), capture size 96 bytes
  3. 000000 00:11:43:e3:6c:dd > 00:22:19:81:01:14, ethertype IPv4 (0x0800), length 74: (tos 0x0, ttl 32, id 1822, offset 0, flags [none], proto ICMP (1), length 60) 10.148.204.38 > 172.22.10.8: ICMP echo request, id 512, seq 43059, length 40
  4. 000122 00:22:19:81:01:14 > 00:0f:1f:f8:c6:ca, ethertype IPv4 (0x0800), length 74: (tos 0x0, ttl 31, id 1822, offset 0, flags [none], proto ICMP (1), length 60) 10.148.204.38 > 172.22.10.8: ICMP echo request, id 512, seq 43059, length 40
  5. 000019 00:0f:1f:f8:c6:ca > 00:22:19:81:01:14, ethertype IPv4 (0x0800), length 74: (tos 0x0, ttl 128, id 14353, offset 0, flags [none], proto ICMP (1), length 60) 172.22.10.8 > 10.148.204.38: ICMP echo reply, id 512, seq 43059, length 40
  6. 000013 00:22:19:81:01:14 > 00:0f:1f:f8:c6:ca, ethertype IPv4 (0x0800), length 102: (tos 0xc0, ttl 64, id 53139, offset 0, flags [none], proto ICMP (1), length 88) 172.22.10.1 > 172.22.10.8: ICMP redirect 10.148.204.38 to host 10.148.204.38, length 68
  7. (tos 0x0, ttl 127, id 14353, offset 0, flags [none], proto ICMP (1), length 60) 172.22.10.8 > 10.148.204.38: ICMP echo reply, id 512, seq 43059, length 40
  8. 000003 00:22:19:81:01:14 > 00:11:43:e3:6c:dd, ethertype IPv4 (0x0800), length 74: (tos 0x0, ttl 127, id 14353, offset 0, flags [none], proto ICMP (1), length 60) 172.22.10.8 > 10.148.204.38: ICMP echo reply, id 512, seq 43059, length 40
  9. 043698 00:22:19:81:01:14 > 00:11:43:e3:6c:dd, ethertype IPv4 (0x0800), length 316: (tos 0xc0, ttl 64, id 33658, offset 0, flags [none], proto ICMP (1), length 302) 10.148.204.12 > 10.148.204.38: ICMP redirect 172.22.10.8 to host 172.22.10.8, length 282
  10. (tos 0x0, ttl 127, id 1853, offset 0, flags [DF], proto TCP (6), length 274) 10.148.204.38.4224 > 172.22.10.8.445: P 4139644337:4139644559(222) ack 3397666302 win 64818 <nop,nop,timestamp 7172947 49333509>
  11. 000295 00:22:19:81:01:14 > 00:0f:1f:f8:c6:ca, ethertype IPv4 (0x0800), length 214: (tos 0xc0, ttl 64, id 53140, offset 0, flags [none], proto ICMP (1), length 200) 172.22.10.1 > 172.22.10.8: ICMP redirect 10.148.204.38 to host 10.148.204.38, length 180
  12. (tos 0x0, ttl 127, id 14375, offset 0, flags [DF], proto TCP (6), length 172) 172.22.10.8.445 > 10.148.204.38.4224: P 1:121(120) ack 222 win 64200 <nop,nop,timestamp 49333509 7172947>
  13. 219435 00:22:19:81:01:14 > 00:11:43:e3:6c:dd, ethertype IPv4 (0x0800), length 94: (tos 0xc0, ttl 64, id 33659, offset 0, flags [none], proto ICMP (1), length 80) 10.148.204.12 > 10.148.204.38: ICMP redirect 172.22.10.8 to host 172.22.10.8, length 60
  14. (tos 0x0, ttl 127, id 2102, offset 0, flags [DF], proto TCP (6), length 52) 10.148.204.38.4224 > 172.22.10.8.445: ., cksum 0x9514 (correct), 1782:1782(0) ack 1273 win 65013 <nop,nop,timestamp 7172951 49333511>
  15. 2. 740392 00:11:43:e3:6c:dd > 00:22:19:81:01:14, ethertype IPv4 (0x0800), length 74: (tos 0x0, ttl 32, id 4530, offset 0, flags [none], proto ICMP (1), length 60) 10.148.204.38 > 172.22.10.8: ICMP echo request, id 512, seq 43827, length 40
  16. 000017 00:22:19:81:01:14 > 00:0f:1f:f8:c6:ca, ethertype IPv4 (0x0800), length 74: (tos 0x0, ttl 31, id 4530, offset 0, flags [none], proto ICMP (1), length 60) 10.148.204.38 > 172.22.10.8: ICMP echo request, id 512, seq 43827, length 40
  17. 000147 00:0f:1f:f8:c6:ca > 00:22:19:81:01:14, ethertype IPv4 (0x0800), length 74: (tos 0x0, ttl 128, id 14387, offset 0, flags [none], proto ICMP (1), length 60) 172.22.10.8 > 10.148.204.38: ICMP echo reply, id 512, seq 43827, length 40
  18. 000017 00:22:19:81:01:14 > 00:0f:1f:f8:c6:ca, ethertype IPv4 (0x0800), length 102: (tos 0xc0, ttl 64, id 53141, offset 0, flags [none], proto ICMP (1), length 88) 172.22.10.1 > 172.22.10.8: ICMP redirect 10.148.204.38 to host 10.148.204.38, length 68
  19. (tos 0x0, ttl 127, id 14387, offset 0, flags [none], proto ICMP (1), length 60) 172.22.10.8 > 10.148.204.38: ICMP echo reply, id 512, seq 43827, length 40
  20. 000007 00:22:19:81:01:14 > 00:11:43:e3:6c:dd, ethertype IPv4 (0x0800), length 74: (tos 0x0, ttl 127, id 14387, offset 0, flags [none], proto ICMP (1), length 60) 172.22.10.8 > 10.148.204.38: ICMP echo reply, id 512, seq 43827, length 40
  21. 6. 097679 00:1b:21:2a:be:a9 > 00:22:19:81:01:14, ethertype IPv4 (0x0800), length 78: (tos 0x0, ttl 127, id 3539, offset 0, flags [none], proto ICMP (1), length 64) 10.148.204.5 > 172.22.10.4: ICMP echo request, id 11274, seq 256, length 44
  22. 000017 00:22:19:81:01:14 > 00:11:11:2a:4a:2d, ethertype IPv4 (0x0800), length 78: (tos 0x0, ttl 126, id 3539, offset 0, flags [none], proto ICMP (1), length 64) 10.148.204.5 > 172.22.10.4: ICMP echo request, id 11274, seq 256, length 44
  23. 000251 00:11:11:2a:4a:2d > 00:22:19:81:01:14, ethertype IPv4 (0x0800), length 78: (tos 0x0, ttl 128, id 32312, offset 0, flags [none], proto ICMP (1), length 64) 172.22.10.4 > 10.148.204.5: ICMP echo reply, id 11274, seq 256, length 44
  24. 000011 00:22:19:81:01:14 > 00:11:11:2a:4a:2d, ethertype IPv4 (0x0800), length 106: (tos 0xc0, ttl 64, id 54063, offset 0, flags [none], proto ICMP (1), length 92) 172.22.10.1 > 172.22.10.4: ICMP redirect 10.148.204.5 to host 10.148.204.5, length 72
  25. (tos 0x0, ttl 127, id 32312, offset 0, flags [none], proto ICMP (1), length 64) 172.22.10.4 > 10.148.204.5: ICMP echo reply, id 11274, seq 256, length 44
  26. 000002 00:22:19:81:01:14 > 00:50:56:a2:00:04, ethertype IPv4 (0x0800), length 78: (tos 0x0, ttl 127, id 32312, offset 0, flags [none], proto ICMP (1), length 64) 172.22.10.4 > 10.148.204.5: ICMP echo reply, id 11274, seq 256, length 44
  27. 000960 00:50:56:a2:00:04 > 00:22:19:81:01:14, ethertype IPv4 (0x0800), length 78: (tos 0x0, ttl 128, id 3540, offset 0, flags [none], proto ICMP (1), length 64) 10.148.204.5 > 172.22.11.2: ICMP echo request, id 9226, seq 256, length 44
  28. 000018 00:22:19:81:01:14 > 00:1b:21:2a:be:a9, ethertype IPv4 (0x0800), length 78: (tos 0x0, ttl 127, id 3540, offset 0, flags [none], proto ICMP (1), length 64) 10.148.204.5 > 172.22.11.2: ICMP echo request, id 9226, seq 256, length 44
  29. 001039 00:50:56:a2:00:04 > 00:22:19:81:01:14, ethertype IPv4 (0x0800), length 78: (tos 0x0, ttl 128, id 3541, offset 0, flags [none], proto ICMP (1), length 64) 10.148.204.5 > 172.22.12.6: ICMP echo request, id 13322, seq 256, length 44
  30. 000017 00:22:19:81:01:14 > 00:1b:21:2a:be:a9, ethertype IPv4 (0x0800), length 78: (tos 0x0, ttl 127, id 3541, offset 0, flags [none], proto ICMP (1), length 64) 10.148.204.5 > 172.22.12.6: ICMP echo request, id 13322, seq 256, length 44
  31. 2. 284094 00:22:19:81:01:14 > 00:11:43:e3:6c:dd, ethertype IPv4 (0x0800), length 139: (tos 0xc0, ttl 64, id 33661, offset 0, flags [none], proto ICMP (1), length 125) 10.148.204.12 > 10.148.204.38: ICMP redirect 172.22.10.8 to host 172.22.10.8, length 105
  32. (tos 0x0, ttl 127, id 11172, offset 0, flags [DF], proto TCP (6), length 97) 10.148.204.38.4224 > 172.22.10.8.445: P 1782:1827(45) ack 1273 win 65013 <nop,nop,timestamp 7173061 49333511>
  33. 000265 00:22:19:81:01:14 > 00:0f:1f:f8:c6:ca, ethertype IPv4 (0x0800), length 133: (tos 0xc0, ttl 64, id 53142, offset 0, flags [none], proto ICMP (1), length 119) 172.22.10.1 > 172.22.10.8: ICMP redirect 10.148.204.38 to host 10.148.204.38, length 99
  34. (tos 0x0, ttl 127, id 14389, offset 0, flags [DF], proto TCP (6), length 91) 172.22.10.8.445 > 10.148.204.38.4224: P 1273:1312(39) ack 1827 win 64162 <nop,nop,timestamp 49333623 7173061>
  35. 1. 841842 00:50:56:a2:00:02 > 00:22:19:81:01:14, ethertype IPv4 (0x0800), length 98: (tos 0x0, ttl 64, id 0, offset 0, flags [DF], proto ICMP (1), length 84) 10.148.204.27 > 10.148.204.12: ICMP echo request, id 6205, seq 1, length 64
  36. 000019 00:22:19:81:01:14 > 00:50:56:a2:00:02, ethertype IPv4 (0x0800), length 98: (tos 0x0, ttl 64, id 63800, offset 0, flags [none], proto ICMP (1), length 84) 10.148.204.12 > 10.148.204.27: ICMP echo reply, id 6205, seq 1, length 64
  37. 997469 00:50:56:a2:00:02 > 00:22:19:81:01:14, ethertype IPv4 (0x0800), length 98: (tos 0x0, ttl 64, id 0, offset 0, flags [DF], proto ICMP (1), length 84) 10.148.204.27 > 10.148.204.12: ICMP echo request, id 6205, seq 2, length 64
  38. 000013 00:22:19:81:01:14 > 00:50:56:a2:00:02, ethertype IPv4 (0x0800), length 98: (tos 0x0, ttl 64, id 63801, offset 0, flags [none], proto ICMP (1), length 84) 10.148.204.12 > 10.148.204.27: ICMP echo reply, id 6205, seq 2, length 64
  39. 993927 00:50:56:a2:00:04 > 00:22:19:81:01:14, ethertype IPv4 (0x0800), length 78: (tos 0x0, ttl 128, id 5161, offset 0, flags [none], proto ICMP (1), length 64) 10.148.204.5 > 172.22.11.3: ICMP echo request, id 13322, seq 256, length 44
  40. 000018 00:22:19:81:01:14 > 00:1b:21:2a:be:a9, ethertype IPv4 (0x0800), length 78: (tos 0x0, ttl 127, id 5161, offset 0, flags [none], proto ICMP (1), length 64) 10.148.204.5 > 172.22.11.3: ICMP echo request, id 13322, seq 256, length 44
  41. 007602 00:50:56:a2:00:02 > 00:22:19:81:01:14, ethertype IPv4 (0x0800), length 98: (tos 0x0, ttl 64, id 0, offset 0, flags [DF], proto ICMP (1), length 84) 10.148.204.27 > 10.148.204.12: ICMP echo request, id 6205, seq 3, length 64
  42. 000013 00:22:19:81:01:14 > 00:50:56:a2:00:02, ethertype IPv4 (0x0800), length 98: (tos 0x0, ttl 64, id 63802, offset 0, flags [none], proto ICMP (1), length 84) 10.148.204.12 > 10.148.204.27: ICMP echo reply, id 6205, seq 3, length 64
  43. 1. 000490 00:50:56:a2:00:02 > 00:22:19:81:01:14, ethertype IPv4 (0x0800), length 98: (tos 0x0, ttl 64, id 0, offset 0, flags [DF], proto ICMP (1), length 84) 10.148.204.27 > 10.148.204.12: ICMP echo request, id 6205, seq 4, length 64
  44. 000013 00:22:19:81:01:14 > 00:50:56:a2:00:02, ethertype IPv4 (0x0800), length 98: (tos 0x0, ttl 64, id 63803, offset 0, flags [none], proto ICMP (1), length 84) 10.148.204.12 > 10.148.204.27: ICMP echo reply, id 6205, seq 4, length 64
  45. 14. 327011 00:50:56:a2:00:04 > 00:22:19:81:01:14, ethertype IPv4 (0x0800), length 78: (tos 0x0, ttl 128, id 9701, offset 0, flags [none], proto ICMP (1), length 64) 10.148.204.5 > 172.22.12.100: ICMP echo request, id 13322, seq 256, length 44
  46. 000021 00:22:19:81:01:14 > 00:1b:21:2a:be:a9, ethertype IPv4 (0x0800), length 78: (tos 0x0, ttl 127, id 9701, offset 0, flags [none], proto ICMP (1), length 64) 10.148.204.5 > 172.22.12.100: ICMP echo request, id 13322, seq 256, length 44
  47. 011521 00:50:56:a2:00:04 > 00:22:19:81:01:14, ethertype IPv4 (0x0800), length 78: (tos 0x0, ttl 128, id 9702, offset 0, flags [none], proto ICMP (1), length 64) 10.148.204.5 > 172.22.12.101: ICMP echo request, id 14346, seq 256, length 44
  48. 000020 00:22:19:81:01:14 > 00:1b:21:2a:be:a9, ethertype IPv4 (0x0800), length 78: (tos 0x0, ttl 127, id 9702, offset 0, flags [none], proto ICMP (1), length 64) 10.148.204.5 > 172.22.12.101: ICMP echo request, id 14346, seq 256, length 44
  49. 6. 130396 00:1b:21:2a:be:a9 > 00:22:19:81:01:14, ethertype IPv4 (0x0800), length 74: (tos 0x0, ttl 31, id 10609, offset 0, flags [none], proto ICMP (1), length 60) 10.148.204.5 > 172.22.10.8: ICMP echo request, id 512, seq 65128, length 40
  50. 000020 00:22:19:81:01:14 > 00:0f:1f:f8:c6:ca, ethertype IPv4 (0x0800), length 74: (tos 0x0, ttl 30, id 10609, offset 0, flags [none], proto ICMP (1), length 60) 10.148.204.5 > 172.22.10.8: ICMP echo request, id 512, seq 65128, length 40
  51. 000126 00:0f:1f:f8:c6:ca > 00:22:19:81:01:14, ethertype IPv4 (0x0800), length 74: (tos 0x0, ttl 128, id 14412, offset 0, flags [none], proto ICMP (1), length 60) 172.22.10.8 > 10.148.204.5: ICMP echo reply, id 512, seq 65128, length 40
  52. 000011 00:22:19:81:01:14 > 00:0f:1f:f8:c6:ca, ethertype IPv4 (0x0800), length 102: (tos 0xc0, ttl 64, id 53143, offset 0, flags [none], proto ICMP (1), length 88) 172.22.10.1 > 172.22.10.8: ICMP redirect 10.148.204.5 to host 10.148.204.5, length 68
  53. (tos 0x0, ttl 127, id 14412, offset 0, flags [none], proto ICMP (1), length 60) 172.22.10.8 > 10.148.204.5: ICMP echo reply, id 512, seq 65128, length 40
  54. 000003 00:22:19:81:01:14 > 00:50:56:a2:00:04, ethertype IPv4 (0x0800), length 74: (tos 0x0, ttl 127, id 14412, offset 0, flags [none], proto ICMP (1), length 60) 172.22.10.8 > 10.148.204.5: ICMP echo reply, id 512, seq 65128, length 40
  55. 1. 440228 00:22:19:81:01:14 > 00:11:11:2a:4a:2d, ethertype IPv4 (0x0800), length 98: (tos 0xc0, ttl 64, id 54064, offset 0, flags [none], proto ICMP (1), length 84) 172.22.10.1 > 172.22.10.4: ICMP redirect 10.148.204.38 to host 10.148.204.38, length 64
  56. (tos 0x0, ttl 127, id 32317, offset 0, flags [DF], proto TCP (6), length 56) 172.22.10.4.135 > 10.148.204.38.4227: S 3062309075:3062309075(0) ack 2731332201 win 8192 <mss 1460,sackOK,timestamp 184100525[|tcp]>
  57. 047203 00:22:19:81:01:14 > 00:11:43:e3:6c:dd, ethertype IPv4 (0x0800), length 590: (tos 0xc0, ttl 64, id 33663, offset 0, flags [none], proto ICMP (1), length 576) 10.148.204.12 > 10.148.204.38: ICMP redirect 172.22.10.4 to host 172.22.10.4, length 556
  58. (tos 0x0, ttl 127, id 2873, offset 0, flags [DF], proto TCP (6), length 657) 10.148.204.38.4229 > 172.22.10.4.49157: P 2891309589:2891310194(605) ack 4099716855 win 65535 <nop,nop,timestamp 7173329 184100526>
  59. 012702 00:22:19:81:01:14 > 00:11:11:2a:4a:2d, ethertype IPv4 (0x0800), length 590: (tos 0xc0, ttl 64, id 54065, offset 0, flags [none], proto ICMP (1), length 576) 172.22.10.1 > 172.22.10.4: ICMP redirect 10.148.204.38 to host 10.148.204.38, length 556
  60. (tos 0x0, ttl 127, id 32328, offset 0, flags [DF], proto TCP (6), length 1313) 172.22.10.4.49157 > 10.148.204.38.4229: P 1:1262(1261) ack 605 win 63797 <nop,nop,timestamp 184100529 7173329>
  61. 125664 00:22:19:81:01:14 > 00:11:43:e3:6c:dd, ethertype IPv4 (0x0800), length 94: (tos 0xc0, ttl 64, id 33664, offset 0, flags [none], proto ICMP (1), length 80) 10.148.204.12 > 10.148.204.38: ICMP redirect 172.22.10.4 to host 172.22.10.4, length 60
  62. (tos 0x0, ttl 127, id 3017, offset 0, flags [DF], proto TCP (6), length 52) 10.148.204.38.4227 > 172.22.10.4.135: ., cksum 0xe455 (correct), 273:273(0) ack 325 win 65211 <nop,nop,timestamp 7173331 184100525>
  63. 619366 00:1b:21:2a:be:a9 > 00:22:19:81:01:14, ethertype IPv4 (0x0800), length 74: (tos 0x0, ttl 31, id 10891, offset 0, flags [none], proto ICMP (1), length 60) 10.148.204.5 > 172.22.10.8: ICMP echo request, id 512, seq 65384, length 40
  64. 000017 00:22:19:81:01:14 > 00:0f:1f:f8:c6:ca, ethertype IPv4 (0x0800), length 74: (tos 0x0, ttl 30, id 10891, offset 0, flags [none], proto ICMP (1), length 60) 10.148.204.5 > 172.22.10.8: ICMP echo request, id 512, seq 65384, length 40
  65. 000127 00:0f:1f:f8:c6:ca > 00:22:19:81:01:14, ethertype IPv4 (0x0800), length 74: (tos 0x0, ttl 128, id 14415, offset 0, flags [none], proto ICMP (1), length 60) 172.22.10.8 > 10.148.204.5: ICMP echo reply, id 512, seq 65384, length 40
  66. 000010 00:22:19:81:01:14 > 00:0f:1f:f8:c6:ca, ethertype IPv4 (0x0800), length 102: (tos 0xc0, ttl 64, id 53144, offset 0, flags [none], proto ICMP (1), length 88) 172.22.10.1 > 172.22.10.8: ICMP redirect 10.148.204.5 to host 10.148.204.5, length 68
  67. (tos 0x0, ttl 127, id 14415, offset 0, flags [none], proto ICMP (1), length 60) 172.22.10.8 > 10.148.204.5: ICMP echo reply, id 512, seq 65384, length 40
  68. 000003 00:22:19:81:01:14 > 00:50:56:a2:00:04, ethertype IPv4 (0x0800), length 74: (tos 0x0, ttl 127, id 14415, offset 0, flags [none], proto ICMP (1), length 60) 172.22.10.8 > 10.148.204.5: ICMP echo reply, id 512, seq 65384, length 40
  69. 7. 554267 00:22:19:81:01:14 > 00:11:11:2a:4a:2d, ethertype IPv4 (0x0800), length 138: (tos 0xc0, ttl 64, id 54067, offset 0, flags [none], proto ICMP (1), length 124) 172.22.10.1 > 172.22.10.4: ICMP redirect 10.148.204.38 to host 10.148.204.38, length 104
  70. (tos 0x0, ttl 127, id 32333, offset 0, flags [DF], proto UDP (17), length 96) 172.22.10.4.137 > 10.148.204.38.137:
  71. >>> NBT UDP PACKET(137): REFRESH(8); REQUEST; UNICAST
  72. TrnID=0xF55F
  73. OpCode=8
  74. NmFlags=0x0
  75. Rcode=0
  76. QueryCount=1
  77. AnswerCount=0
  78. AuthorityCount=0
  79. AddressRecCount=1
  80. QuestionRecords:
  81. Name=
  82. WARNING: Short packet. Try increasing the snap length
  83.  
  84.  
  85. 1. 500023 00:22:19:81:01:14 > 00:11:11:2a:4a:2d, ethertype IPv4 (0x0800), length 138: (tos 0xc0, ttl 64, id 54068, offset 0, flags [none], proto ICMP (1), length 124) 172.22.10.1 > 172.22.10.4: ICMP redirect 10.148.204.38 to host 10.148.204.38, length 104
  86. (tos 0x0, ttl 127, id 32334, offset 0, flags [DF], proto UDP (17), length 96) 172.22.10.4.137 > 10.148.204.38.137:
  87. >>> NBT UDP PACKET(137): REFRESH(8); REQUEST; UNICAST
  88. TrnID=0xF55F
  89. OpCode=8
  90. NmFlags=0x0
  91. Rcode=0
  92. QueryCount=1
  93. AnswerCount=0
  94. AuthorityCount=0
  95. AddressRecCount=1
  96. QuestionRecords:
  97. Name=
  98. WARNING: Short packet. Try increasing the snap length
  99.  
  100.  
  101. ^C
  102. 54 packets captured
  103. 54 packets received by filter
  104. 0 packets dropped by kernel
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement