From owner-freebsd-net@freebsd.org Tue Feb 6 21:48:37 2018 Return-Path: Delivered-To: freebsd-net@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 50FB0F0A056 for ; Tue, 6 Feb 2018 21:48:37 +0000 (UTC) (envelope-from alarig@swordarmor.fr) Received: from togepi.gozmail.bzh (togepi.gozmail.bzh [IPv6:2a00:5884:124::1]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id D353D83A42 for ; Tue, 6 Feb 2018 21:48:36 +0000 (UTC) (envelope-from alarig@swordarmor.fr) Received: from mew.swordarmor.fr (mew.swordarmor.fr [IPv6:2a00:5884:102:1::4]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) (Authenticated sender: alarig@swordarmor.fr) by togepi.gozmail.bzh (Postfix) with ESMTPSA id BACFE1A0075 for ; Tue, 6 Feb 2018 22:48:25 +0100 (CET) DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=swordarmor.fr; s=default; t=1517953705; bh=PREgAUv4Z2ia6BUPWP6e0Ufk8xgFF0mPdTe8ilRssIo=; h=Date:From:To:Subject:References:In-Reply-To:From; b=Cd3UOCm8nLg7cqK6RXRwUQywGvnpCh+OEFbZWw+FZkwue74XPIZPrHJKN/IzvPyhL d9OOfYXBgjtX+sTwEQX84YNe7/yaiUiHEVUfYNwXpK1YlHGw1mN3vLPgcM4SE1RXT+ 2r9Z7+kMsvQixtS5+Wu5TBAEyyY4V0p3oDLyER7E= Date: Tue, 6 Feb 2018 22:48:22 +0100 From: Alarig Le Lay To: freebsd-net@freebsd.org Subject: Re: tcpdump filter not functioning correctly with igb on FreeBSD 11.1 Message-ID: <20180206214822.szvxjuassxzvs6sd@mew.swordarmor.fr> References: <95AA0EAB-B3D6-4E68-83B2-914894D6FB90@truespeed.com> <5A7A1657.4050706@grosbein.net> MIME-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="376qcw4ifjsazvty" Content-Disposition: inline In-Reply-To: User-Agent: NeoMutt/20171208 X-BeenThere: freebsd-net@freebsd.org X-Mailman-Version: 2.1.25 Precedence: list List-Id: Networking and TCP/IP with FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 06 Feb 2018 21:48:37 -0000 --376qcw4ifjsazvty Content-Type: text/plain; charset=utf-8 Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On mar. 6 f=C3=A9vr. 21:03:12 2018, David Athay wrote: > I was originally using 11.1-RELEASE but I have since updated to 11-STABLE= =2E Weirdness still persists >=20 > $ tcpdump --version > tcpdump version 4.9.2 > libpcap version 1.8.1 > OpenSSL 1.0.2n-freebsd 7 Dec 2017 >=20 > $ uname -aUK > FreeBSD s5.pkfm.banes 11.1-STABLE FreeBSD 11.1-STABLE #2 r328930: Tue Feb= 6 16:05:59 GMT 2018 root@s5.pkfm.banes:/usr/obj/usr/src/sys/TRUESPEED= amd64 1101509 1101509 On an older tcpdump version (from pkg), I have the expected behaviour here. root@budic:~ # tcpdump -c 4 -i igb2 host conan.grif =20 tcpdump: verbose output suppressed, use -v or -vv for full protocol decode listening on igb2, link-type EN10MB (Ethernet), capture size 262144 bytes 22:45:06.889186 IP conan.grif.37865 > budic.grif.snmp: GetBulk(29) N=3D0 = M=3D10 interfaces.ifTable.ifEntry.ifOutErrors 22:45:06.890378 IP budic.grif.snmp > conan.grif.37865: GetResponse(185) i= nterfaces.ifTable.ifEntry.ifOutErrors.1=3D0 interfaces.ifTable.ifEntry.ifOu= tErrors.2=3D0 interfaces.ifTable.ifEntry.ifOutErrors.3=3D0 interfaces.ifTab= le.ifEntry.ifOutErrors.4=3D0 interfaces.ifTable.ifEntry.ifOutErrors.5=3D3 i= nterfaces.ifTable.ifEntry.ifOutErrors.6=3D3 interfaces.ifTable.ifEntry.ifOu= tErrors.7=3D2 interfaces.ifTable.ifEntry.ifOutErrors.8=3D7 interfaces.ifTab= le.ifEntry.ifOutErrors.9=3D5 interfaces.ifTable.ifEntry.ifOutErrors.10=3D5 22:45:06.892503 IP conan.grif.37865 > budic.grif.snmp: GetBulk(30) N=3D0 = M=3D10 interfaces.ifTable.ifEntry.ifOutErrors.10 22:45:06.893577 IP budic.grif.snmp > conan.grif.37865: GetResponse(185) i= nterfaces.ifTable.ifEntry.ifOutErrors.11=3D3 interfaces.ifTable.ifEntry.ifO= utErrors.12=3D2 interfaces.ifTable.ifEntry.ifOutErrors.13=3D2 interfaces.if= Table.ifEntry.ifOutErrors.14=3D3 interfaces.ifTable.ifEntry.ifOutErrors.15= =3D1 interfaces.ifTable.ifEntry.ifOutErrors.16=3D0 interfaces.ifTable.ifEnt= ry.ifOutQLen.1=3D0 interfaces.ifTable.ifEntry.ifOutQLen.2=3D0 interfaces.if= Table.ifEntry.ifOutQLen.3=3D0 interfaces.ifTable.ifEntry.ifOutQLen.4=3D0 4 packets captured =20 5 packets received by filter =20 0 packets dropped by kernel =20 root@budic:~ # tcpdump -c 4 -i igb2 not host conan.grif =20 tcpdump: verbose output suppressed, use -v or -vv for full protocol decode listening on igb2, link-type EN10MB (Ethernet), capture size 262144 bytes 22:45:15.139058 IP guerech.grif.5404 > 239.192.26.70.5405: UDP, length 136 22:45:15.442807 IP guerech.grif.5404 > 239.192.26.70.5405: UDP, length 136 22:45:15.506901 ARP, Request who-has 172.17.0.28 tell berthe.grif, length 46 22:45:15.746589 IP guerech.grif.5404 > 239.192.26.70.5405: UDP, length 136 4 packets captured =20 16 packets received by filter 0 packets dropped by kernel =20 root@budic:~ # tcpdump --version tcpdump version 4.9.0 libpcap version 1.8.1 OpenSSL 1.0.2k-freebsd 26 Jan 2017 root@budic:~ # uname -aUK FreeBSD budic.cogent-rns.grifon.fr 11.1-RELEASE FreeBSD 11.1-RELEASE #0 r32= 1309: Fri Jul 21 02:08:28 UTC 2017 root@releng2.nyi.freebsd.org:/usr/ob= j/usr/src/sys/GENERIC amd64 1101001 1101001 --=20 alarig --376qcw4ifjsazvty Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQEzBAABCAAdFiEE+2yGwT0H0n57WkRbrzhKwWsgK4gFAlp6IqAACgkQrzhKwWsg K4g5Gwf/VuVS2T5LE/sZc9vR1DjO2fm4Y8rn2OtScq15aA3tF/B0Giww4//MjUR3 pg9xQUJys/wGFd0Klo+0yrBBAVmzplQ33FWx8csY+F7CPktZCGN8G74i+uZJ6VFT GG2rLqWYTJtgcW5ZGybi86HGi2VMge13nwePYEJavLQbMNKgIN2AnihviSk7wpDk Leziaj8E1PvqBVTBBwdGSxewxtV7MKFnoOjlL1OJZTi9rdr7SpUSfl/ibWHcJGtD oWcKYRbdGNtk4Ba+ew+8q63smXX7BJ/Ybnv1yqt9NR7pgyEeVc85JCu2YRD5wbYF DmvCF+zeiMjcPSRgNXrZU5kGEYkapg== =y+Fo -----END PGP SIGNATURE----- --376qcw4ifjsazvty--