From owner-freebsd-net@freebsd.org Wed Feb 7 09:43:57 2018 Return-Path: Delivered-To: freebsd-net@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 0AEA1EEE213 for ; Wed, 7 Feb 2018 09:43:57 +0000 (UTC) (envelope-from alarig@swordarmor.fr) Received: from togepi.gozmail.bzh (togepi.gozmail.bzh [IPv6:2a00:5884:124::1]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 9EEDB7FF55 for ; Wed, 7 Feb 2018 09:43:56 +0000 (UTC) (envelope-from alarig@swordarmor.fr) Received: from mew.swordarmor.fr (mew.swordarmor.fr [IPv6:2a00:5884:102:1::4]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) (Authenticated sender: alarig@swordarmor.fr) by togepi.gozmail.bzh (Postfix) with ESMTPSA id B792D1A0075 for ; Wed, 7 Feb 2018 10:43:53 +0100 (CET) DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=swordarmor.fr; s=default; t=1517996633; bh=vaWdIOcSpPBdXJ/B4cip50BuqGj6MoTo9x0kAuIo0Xg=; h=Date:From:To:Subject:References:In-Reply-To:From; b=gtbNsAaZTGesmRZFUV2eDxurhEHfyYGe9SznF+UsDzNZizXJdQUIfVzpFTrS9sDnM 7BQdFubyNbc4QpxLKaJEls1BxF0s2SR0swaH9Xi0OWxGT3Rs5LsASw98f3rxgSttSr geWaVd6Uvo3ZnSscqDD/B43jXuVqE5JnV7kezvHI= Date: Wed, 7 Feb 2018 10:43:53 +0100 From: Alarig Le Lay To: freebsd-net@freebsd.org Subject: Re: tcpdump filter not functioning correctly with igb on FreeBSD 11.1 Message-ID: <20180207094353.2rgaikzagjqhimde@mew.swordarmor.fr> References: <5A7A1657.4050706@grosbein.net> <5A7A19DD.6050400@grosbein.net> <64C4AA32-5A49-4D6F-B7A7-93CDB0E59F09@truespeed.com> <5A7A24DC.0@grosbein.net> <293C7809-A1AE-4040-8963-F9A6802CB898@truespeed.com> <5A7A29D6.3050307@grosbein.net> <5A7A3079.4080404@grosbein.net> <28A5CF82-5091-42AA-8C91-C190BAFF5F30@truespeed.com> MIME-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="mz6vwya64352oco7" Content-Disposition: inline In-Reply-To: <28A5CF82-5091-42AA-8C91-C190BAFF5F30@truespeed.com> User-Agent: NeoMutt/20171208 X-BeenThere: freebsd-net@freebsd.org X-Mailman-Version: 2.1.25 Precedence: list List-Id: Networking and TCP/IP with FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 07 Feb 2018 09:43:57 -0000 --mz6vwya64352oco7 Content-Type: text/plain; charset=utf-8 Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On mar. 6 f=C3=A9vr. 22:49:54 2018, David Athay wrote: >=20 >=20 > > On 6 Feb 2018, at 22:47, Eugene Grosbein wrote: > >=20 > > Well, that explains everything. You should use "vlan and not port > > 22" and "vlan and host X.X.X.X" (same without "not") when filtering > > vlan-tagged traffic as documented in the pcap-filter(7) manual page > > or else you get wrong results. "Works as intended". > >=20 > > Deinstall extra tcpdump/libcap packages, if you do not need them. > >=20 > >=20 >=20 > That worked, thanks! If you want to use only 'host' or 'port', you could also tcpdump on the tagged interface. --=20 alarig --mz6vwya64352oco7 Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQEzBAABCAAdFiEE+2yGwT0H0n57WkRbrzhKwWsgK4gFAlp6ylYACgkQrzhKwWsg K4iAggf9FvGDzNqBvPzCO7uFmDTSl4x6MeIeWkeHdaHXgoC0iDUMRdv62BlgFmRp kP7yhaQ535AeiM2OnO+UL7Z+lqEW2Lh2F/6igtV6HPJmUn6MXWz33gGEy9XeZ5K4 NFV+cnSAG8gRrSGywN+V/BXxYx2BcGCflPVKlgiHEkSz1mtIx0SFwPbHaAgIgisV GrMpNhN59T9AdhGERLuScwa0yB68V+xkvdxN30HjlCpTIEV4suv1CcBEax3rTOb2 LtSpSR8ASRZXTzxev360PTve09TeUspy8k4mqKRiPdE29dzIRT3OHt3UH/akHbE8 dvWm7pTP4vuX2e7+LTUVMnC9Owbjpw== =LyRu -----END PGP SIGNATURE----- --mz6vwya64352oco7--