Linux, FreeBSD, Juniper, Cisco / Network security articles and troubleshooting guides

FAQ
It is currently Fri Dec 01, 2023 12:54 am


Internet Protocol, Transport Control Protocol, Network protocols, Routing, Routers, IP aliases, Routes, Ethernet

Author Message
mandrei99
Post  Post subject: FreeBSD tcpdump on enc0 doesn't show any traffic  |  Posted: Fri Jun 21, 2013 8:54 am

Joined: Tue Aug 04, 2009 9:16 am
Posts: 250

Offline
 

FreeBSD tcpdump on enc0 doesn't show any traffic

FreeBSD supports enc0 pseudo interface (kernel "device enc") that is used for ipsec tunnels. The external interface will show encrypted traffic and enc0 interface will show unencrypted traffic.

If tcpdump doesn't show any packets on enc0 interface, that is most probably because it is not up. Example:

Code:
[root@host]# ifconfig enc0
enc0: flags=0<> metric 0 mtu 1536
        nd6 options=29<PERFORMNUD,IFDISABLED,AUTO_LINKLOCAL>



Bring up the interface and you will start seeing packets with tcpdump:
Code:
[root@host]# ifconfig enc0 up
[root@host]# ifconfig enc0
enc0: flags=41<UP,RUNNING> metric 0 mtu 1536
        nd6 options=29<PERFORMNUD,IFDISABLED,AUTO_LINKLOCAL>
[root@host]# tcpdump -nni enc0
tcpdump: WARNING: enc0: no IPv4 address assigned
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on enc0, link-type ENC (OpenBSD encapsulated IP), capture size 65535 bytes
12:45:11.083481 (authentic,confidential): SPI 0x0f9d1bcb: IP 10.1.20.1 > 10.1.20.2: IP 172.16.3.1 > 172.16.3.2: ICMP echo request, id 6434, seq 556, length 64 (ipip-proto-4)
12:45:12.095905 (authentic,confidential): SPI 0x0f9d1bcb: IP 10.1.20.1 > 10.1.20.2: IP 172.16.3.1 > 172.16.3.2: ICMP echo request, id 6434, seq 557, length 64 (ipip-proto-4)
12:45:13.108132 (authentic,confidential): SPI 0x0f9d1bcb: IP 10.1.20.1 > 10.1.20.2: IP 172.16.3.1 > 172.16.3.2: ICMP echo request, id 6434, seq 558, length 64 (ipip-proto-4)





Top
Display posts from previous:  Sort by  
E-mail friendPrint view

Topics related to - "FreeBSD tcpdump on enc0 doesn't show any traffic"
 Topics   Author   Replies   Views   Last post 
There are no new unread posts for this topic. FreeBSD + IPerf send multicast source traffic via specific interface

mandrei99

3

6228

Sat Apr 11, 2015 5:28 am

areeba View the latest post

There are no new unread posts for this topic. FreeBSD show network interface statistics

mandrei99

0

5688

Wed Sep 25, 2013 9:30 am

mandrei99 View the latest post

There are no new unread posts for this topic. Tcpdump: How to capture first two packets of tcp conversation (SYN/SYN+ACK)

debuser

0

29968

Wed Jun 13, 2012 5:32 am

debuser View the latest post

There are no new unread posts for this topic. FreeBSD PF supported icmp types

admin

0

3217

Fri Jan 28, 2011 9:15 am

admin View the latest post

There are no new unread posts for this topic. FreeBSD - multiple routing tables

mandrei99

0

10462

Wed Aug 28, 2013 8:40 am

mandrei99 View the latest post

There are no new unread posts for this topic. FreeBSD: How to list IPv6 neighbors

mandrei99

0

6066

Mon Oct 06, 2014 10:00 am

mandrei99 View the latest post

There are no new unread posts for this topic. Set up FTP PROXY via command line in Linux/FreeBSD

mandrei99

0

22856

Tue Jan 20, 2015 5:01 pm

mandrei99 View the latest post

There are no new unread posts for this topic. FreeBSD - Adding VLAN Tagged subinterface using ifconfig

admin

0

11132

Mon Aug 19, 2013 10:44 am

admin View the latest post

There are no new unread posts for this topic. FreeBSD list interface multicast group membership

mandrei99

0

4655

Tue Dec 03, 2013 9:02 am

mandrei99 View the latest post

There are no new unread posts for this topic. FreeBSD net.inet.ip.fastforwarding breaks IPSEC tunnels

mandrei99

1

3636

Tue Jan 07, 2014 6:13 am

mandrei99 View the latest post

 

Who is online
Users browsing this forum: No registered users and 0 guests
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum
Jump to:  
cronNews News Site map Site map SitemapIndex SitemapIndex RSS Feed RSS Feed Channel list Channel list


Delete all board cookies | The team | All times are UTC - 5 hours [ DST ]



phpBB SEO