Adam Lazur on Fri, 24 Jan 2003 13:21:04 -0500


[Date Prev] [Date Next] [Thread Prev] [Thread Next] [Date Index] [Thread Index]

[PLUG] Re: sniffers and other ways of scoping packets


mike.h (mike.h@stemik.com) said:
> Call me old fashioned, but I still use tcpdump.(man 8) No GUI crap, just
> fast, efficient, configurable, and free. Standard with every *nix distro
> I've ever seen.

In my experience, tcpdump is good for capturing packets and basic
analysis, but ethereal kicks ass for anything beyond basic "did I get an
ack?" stuff. The display filters and packet disassembly really make a
difference.

In an embedded environment, I usually capture with tcpdump (-s 0) and
analyze the results on a workstation with ethereal.

-- 
Adam Lazur, Cluster Monkey
_________________________________________________________________________
Philadelphia Linux Users Group        --       http://www.phillylinux.org
Announcements - http://lists.netisland.net/mailman/listinfo/plug-announce
General Discussion  --   http://lists.netisland.net/mailman/listinfo/plug