Forum Discussion
cdurski_171657
Nimbostratus
Sep 25, 2014View entire connection through F5
I want to see what happens when a specific IP connects to a virtual server IP, and then is sent to the real server nodes in the pool -- or if it is not I want to see why. How do I track one connecti...
afedden_1985
Cirrus
Sep 25, 2014You didn't say how you wanted this information so I will just throw this out there. We use this method with wireshark to display the tcpdump. The new version 11.2 feature –p captures the peer server side connection with just the client ip in the command! This link has more details http://support.f5.com/kb/en-us/solutions/public/13000/600/sol13637.html This example shows how the command looks with a single client.
tcpdump -ni 0.0:nnnp -s 0 host 10.6.160.92 -w /var/tmp/test1.pcap OR Note, with the “-p” flag, you can narrow down by all traffic to that VIP as well if you put tcpdump -ni 0.0:nnnp -s 0 host and port -w /var/tmp/traffic_to_vip.pcap Example. tcpdump -ni 0.0:nnnp -s 0 host 1.1.1.1 and port 443 -w /var/tmp/traffic_to_vip.pcap
cdurski_171657
Nimbostratus
Sep 25, 2014Looks good to start. Will that just show the connection on one side of the F5, or is it going to give me the entire conversation through the F5? How can I then export that pcap for analysis in a pcap tool? I'm not good with linux.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects