читать дальше »
[root@gw ~]# tcpdump -i eth5 -vv
tcpdump: listening on eth5, link-type EN10MB (Ethernet), capture size 96 bytes
12:51:34.555157 IP (tos 0x0, ttl 128, id 40370, offset 0, flags [DF], proto: TCP (6), length: 783) 192.168.1.5.instl_bootc > 212.47.222.22.http: P 3125538993:3125539736(743) ack 2128970430 win 32768
12:51:34.555309 IP (tos 0x10, ttl 64, id 937, offset 0, flags [DF], proto: TCP (6), length: 172) gw.holda.lan.ssh > 192.168.1.122.sdclient: P 3222147959:3222148091(132) ack 3800102094 win 65535
12:51:34.555608 IP (tos 0x0, ttl 128, id 41400, offset 0, flags [DF], proto: TCP (6), length: 40) 192.168.1.122.sdclient > gw.holda.lan.ssh: ., cksum 0x3322 (correct), 1:1(0) ack 132 win 17268
12:51:34.556320 IP (tos 0x0, ttl 128, id 40371, offset 0, flags [DF], proto: TCP (6), length: 689) 192.168.1.5.remote-as > rev-81-94-239-52.deac.net.http: P 4010020752:4010021401(649) ack 2176481484 win 64411
12:51:34.556764 IP (tos 0x0, ttl 128, id 20634, offset 0, flags [DF], proto: TCP (6), length: 40) 192.168.1.62.4531 > games42.p.mail.ru.843: ., cksum 0x8ba1 (correct), 1168734339:1168734339(0) ack 426581051 win 64191
12:51:34.558656 IP (tos 0x0, ttl 56, id 38870, offset 0, flags [DF], proto: TCP (6), length: 1165) rev-81-94-239-52.deac.net.http > 192.168.1.5.remote-as: P 1:1126(1125) ack 649 win 65535
12:51:34.559787 IP (tos 0x10, ttl 64, id 938, offset 0, flags [DF], proto: TCP (6), length: 284) gw.holda.lan.ssh > 192.168.1.122.sdclient: P 132:376(244) ack 1 win 65535
12:51:34.561018 IP (tos 0x10, ttl 64, id 939, offset 0, flags [DF], proto: TCP (6), length: 284) gw.holda.lan.ssh > 192.168.1.122.sdclient: P 376:620(244) ack 1 win 65535
12:51:34.561161 IP (tos 0x10, ttl 64, id 940, offset 0, flags [DF], proto: TCP (6), length: 284) gw.holda.lan.ssh > 192.168.1.122.sdclient: P 620:864(244) ack 1 win 65535
12:51:34.561350 IP (tos 0x0, ttl 128, id 41401, offset 0, flags [DF], proto: TCP (6), length: 40) 192.168.1.122.sdclient > gw.holda.lan.ssh: ., cksum 0x3322 (correct), 1:1(0) ack 620 win 16780
12:51:34.562375 IP (tos 0x0, ttl 52, id 10612, offset 0, flags [DF], proto: TCP (6), length: 517) 62.84.6.45.http > 192.168.1.5.cognex-insight: P 3160276460:3160276937(477) ack 3966542867 win 69
12:51:34.562387 IP (tos 0x0, ttl 52, id 10613, offset 0, flags [DF], proto: TCP (6), length: 40) 62.84.6.45.http > 192.168.1.5.cognex-insight: F, cksum 0x583b (correct), 477:477(0) ack 1 win 69
12:51:34.562499 IP (tos 0x0, ttl 128, id 40372, offset 0, flags [none], proto: UDP (17), length: 64) 192.168.1.5.56832 > gw.holda.lan.domain: [udp sum ok] 1318+ A? aolv.hit.gemius.pl. (36)
12:51:34.562757 IP (tos 0x0, ttl 52, id 4586, offset 0, flags [none], proto: UDP (17), length: 84) 157.56.106.184.teredo > 192.168.1.170.53175: UDP, length 56
12:51:34.563039 IP (tos 0x0, ttl 128, id 40373, offset 0, flags [DF], proto: TCP (6), length: 40) 192.168.1.5.cognex-insight > 62.84.6.45.http: ., cksum 0xd96e (correct), 1:1(0) ack 478 win 32529
12:51:34.563397 IP (tos 0x0, ttl 128, id 40374, offset 0, flags [DF], proto: TCP (6), length: 40) 192.168.1.5.cognex-insight > 62.84.6.45.http: F, cksum 0xd96d (correct), 1:1(0) ack 478 win 32529
12:51:34.563412 arp who-has 192.168.1.106 tell 192.168.1.170
12:51:34.563443 IP (tos 0x0, ttl 128, id 13926, offset 0, flags [none], proto: UDP (17), length: 80) 192.168.1.170.53175 > 178.215.76.97.61865: [udp sum ok] UDP, length 52
18 packets captured
82 packets received by filter
0 packets dropped by kernel