Forum Discussion
Lay_Hin_53714
Nimbostratus
Dec 19, 2008tcpdump output interpret guide
Hi All,
Is there a document that can explain the output from tcpdump?
For example, I would like to know what S, P and DF means.
15:23:27.351280 202.6.123.44.9632 > 203.116.162.168.ldap: S 2450604975:2450604975(0) win 49640 (DF)
15:23:27.361003 203.116.162.168.ldap > 202.6.123.44.9632: S 3804777917:3804777917(0) ack 2450604976 win 1460 (DF)
15:23:27.361984 202.6.123.44.9632 > 203.116.162.168.ldap: . ack 1 win 49640 (DF)
15:23:27.423022 202.6.123.44.9632 > 203.116.162.168.ldap: P 1:149(148) ack 1 win 49640 (DF)
15:23:29.034865 203.116.162.168.ldap > 202.6.123.44.9632: . ack 149 win 8760 (DF)
15:23:29.133984 203.116.162.168.ldap > 202.6.123.44.9632: P 1:1461(1460) ack 149 win 8760 (DF)
- Lay_Hin_53714
Nimbostratus
Ah... I find following link is quite good in explaining the detail. - Hamish
Cirrocumulus
Hi Layhin. - JRahm
Admin
If you are adventurous, you can download the F5 wireshark plugin (Click here) This requires you to compile wireshark yourself, but the payoff is extra details in the capture files if taken from the bigip. - hoolio
Cirrostratus
Hey Citizen, - JRahm
Admin
most useful item I remember is the connection id so you can match clientside and serverside flows. It's been a few months since I lost the workstation I had it compiled on. - ukstin
Nimbostratus
I´ve compiled wireshark with this plugin and dump a box with bigip 9.4.5 but I compared the data with a default wireshark (without this plugin) and the information is the same. - JRahm
Admin
when you specify the interface, you need to append :000 or :nnn, I can't remember. - hoolio
Cirrostratus
I think it's :nnn - ukstin
Nimbostratus
works with this:
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects