Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 12 Jun 2001 14:51:17 -0500
From:      "Derek O'Flynn" <derekoflynn@hotmail.com>
To:        freebsd-security@freebsd.org
Message-ID:  <F202HD4mZuHlKFlzgbd00005bd8@hotmail.com>

next in thread | raw e-mail | index | archive | help

I have two machines, one running freebsd 4.0, and one running 4.3. They are
physically connected to the same hub (same segment)

When running tcpdump or snort on the 4.0 box, I get traffic from a variety
of protocols

However, when I run tcpdump or snort on the 4.0 box, I get traffic from a
variety of protocols, but no tcp protocol traffic.  The only time tcp
protocol shows up is if I connect to the web server on the 4.3 box from
another machine.

Strangest thing I've ever seen!  Anyway, I thought it might have been cause
I did a minimal installation, and maybe something was disabled, so I setup
the box again with a full install of everything but X, and the same thing is
occurring.  I then thought it was the network card, but that can't be cause
it is receiving tcp packets, but only those destined for the machine,
nothing else on the segment.  Is there a setting that causes it to only see
it's tcp packets (note: it is seeing icmp/udp/arp packets from other
sources)

Does anyone know if there's something weird with 4.3 that would cause this?
I'm running the 4.3 iso image downloaded from freebsd.  It hasn't been
modified at all, standard installation.

_________________________________________________________________
Get your FREE download of MSN Explorer at http://explorer.msn.com


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?F202HD4mZuHlKFlzgbd00005bd8>