Guest User

Untitled

a guest
May 15th, 2020
49
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 12.67 KB | None | 0 0
  1. Thanks for your help
  2. I have run tcpdump like this :
  3. `sudo tcpdump -i any -nn host 192.168.21.6 -vvv -B 4096`
  4.  
  5. For informations, i'm connected with OpenVPN.
  6. The destination machine is : 192.168.10.55
  7. The source (who start ssh connection) is : 192.168.21.6
  8.  
  9. The tcpdump's command output :
  10. ```
  11. tcpdump: listening on any, link-type LINUX_SLL (Linux cooked), capture size 262144 bytes
  12. 11:24:42.193300 IP (tos 0x0, ttl 127, id 43677, offset 0, flags [DF], proto TCP (6), length 52)
  13. 192.168.21.6.50739 > 192.168.10.55.22: Flags [S], cksum 0xac7a (correct), seq 3494809899, win 64240, options [mss 1287,nop,wscale 8,nop,nop,sackOK], length 0
  14. 11:24:42.193463 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  15. 11:24:42.193473 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  16. 11:24:42.193479 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  17. 11:24:42.193484 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  18. 11:24:42.193488 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  19. 11:24:42.193492 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  20. 11:24:42.193497 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  21. 11:24:42.193501 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  22. 11:24:42.193505 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  23. 11:24:42.193511 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  24. 11:24:42.193515 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  25. 11:24:43.194973 IP (tos 0x0, ttl 127, id 43678, offset 0, flags [DF], proto TCP (6), length 52)
  26. 192.168.21.6.50739 > 192.168.10.55.22: Flags [S], cksum 0xac7a (correct), seq 3494809899, win 64240, options [mss 1287,nop,wscale 8,nop,nop,sackOK], length 0
  27. 11:24:43.211214 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  28. 11:24:43.211231 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  29. 11:24:43.211238 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  30. 11:24:43.211243 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  31. 11:24:43.211247 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  32. 11:24:43.211251 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  33. 11:24:43.211256 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  34. 11:24:43.211260 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  35. 11:24:43.211266 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  36. 11:24:43.211270 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  37. 11:24:43.211275 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  38. 11:24:44.235211 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  39. 11:24:44.235229 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  40. 11:24:44.235236 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  41. 11:24:44.235241 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  42. 11:24:44.235245 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  43. 11:24:44.235249 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  44. 11:24:44.235254 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  45. 11:24:44.235258 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  46. 11:24:44.235263 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  47. 11:24:44.235268 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  48. 11:24:44.235273 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  49. 11:24:45.201400 IP (tos 0x0, ttl 127, id 43679, offset 0, flags [DF], proto TCP (6), length 52)
  50. 192.168.21.6.50739 > 192.168.10.55.22: Flags [S], cksum 0xac7a (correct), seq 3494809899, win 64240, options [mss 1287,nop,wscale 8,nop,nop,sackOK], length 0
  51. 11:24:49.200361 IP (tos 0x0, ttl 127, id 43680, offset 0, flags [DF], proto TCP (6), length 52)
  52. 192.168.21.6.50739 > 192.168.10.55.22: Flags [S], cksum 0xac7a (correct), seq 3494809899, win 64240, options [mss 1287,nop,wscale 8,nop,nop,sackOK], length 0
  53. 11:24:49.200443 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  54. 11:24:49.200453 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  55. 11:24:49.200459 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  56. 11:24:49.200463 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  57. 11:24:49.200468 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  58. 11:24:49.200472 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  59. 11:24:49.200477 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  60. 11:24:49.200481 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  61. 11:24:49.200486 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  62. 11:24:49.200490 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  63. 11:24:49.200494 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  64. 11:24:50.219219 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  65. 11:24:50.219237 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  66. 11:24:50.219244 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  67. 11:24:50.219248 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  68. 11:24:50.219253 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  69. 11:24:50.219258 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  70. 11:24:50.219262 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  71. 11:24:50.219267 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  72. 11:24:50.219272 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  73. 11:24:50.219276 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  74. 11:24:50.219281 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  75. 11:24:51.243209 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  76. 11:24:51.243227 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  77. 11:24:51.243234 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  78. 11:24:51.243239 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  79. 11:24:51.243243 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  80. 11:24:51.243248 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  81. 11:24:51.243252 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  82. 11:24:51.243256 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  83. 11:24:51.243261 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  84. 11:24:51.243266 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  85. 11:24:51.243270 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  86. 11:24:57.201069 IP (tos 0x0, ttl 127, id 43681, offset 0, flags [DF], proto TCP (6), length 52)
  87. 192.168.21.6.50739 > 192.168.10.55.22: Flags [S], cksum 0xac7a (correct), seq 3494809899, win 64240, options [mss 1287,nop,wscale 8,nop,nop,sackOK], length 0
  88. 11:24:57.201151 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  89. 11:24:57.201160 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  90. 11:24:57.201166 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  91. 11:24:57.201171 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  92. 11:24:57.201175 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  93. 11:24:57.201179 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  94. 11:24:57.201184 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  95. 11:24:57.201188 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  96. 11:24:57.201192 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  97. 11:24:57.201197 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  98. 11:24:57.201202 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  99. 11:24:58.219215 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  100. 11:24:58.219231 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  101. 11:24:58.219237 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  102. 11:24:58.219242 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  103. 11:24:58.219246 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  104. 11:24:58.219250 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  105. 11:24:58.219254 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  106. 11:24:58.219259 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  107. 11:24:58.219263 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  108. 11:24:58.219268 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  109. 11:24:58.219272 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  110. 11:24:59.243208 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  111. 11:24:59.243224 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  112. 11:24:59.243231 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  113. 11:24:59.243235 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  114. 11:24:59.243240 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  115. 11:24:59.243244 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  116. 11:24:59.243249 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  117. 11:24:59.243253 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  118. 11:24:59.243258 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  119. 11:24:59.243262 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  120. 11:24:59.243266 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.21.6 tell 192.168.10.55, length 28
  121. ^C
  122. 104 packets captured
  123. 104 packets received by filter
  124. 0 packets dropped by kernel
  125. ```
Add Comment
Please, Sign In to add comment