From owner-freebsd-questions@FreeBSD.ORG Mon Mar 21 18:17:38 2005 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id B001E16A4CE for ; Mon, 21 Mar 2005 18:17:38 +0000 (GMT) Received: from dan.emsphone.com (dan.emsphone.com [199.67.51.101]) by mx1.FreeBSD.org (Postfix) with ESMTP id 508FB43D49 for ; Mon, 21 Mar 2005 18:17:38 +0000 (GMT) (envelope-from dan@dan.emsphone.com) Received: (from dan@localhost) by dan.emsphone.com (8.13.1/8.13.1) id j2LIHbfd003036; Mon, 21 Mar 2005 12:17:37 -0600 (CST) (envelope-from dan) Date: Mon, 21 Mar 2005 12:17:37 -0600 From: Dan Nelson To: "Edwin D. Vinas" Message-ID: <20050321181737.GH5243@dan.emsphone.com> References: <36f5bbba0503211004b66957a@mail.gmail.com> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <36f5bbba0503211004b66957a@mail.gmail.com> X-OS: FreeBSD 5.4-PRERELEASE X-message-flag: Outlook Error User-Agent: Mutt/1.5.8i cc: freebsd-questions@freebsd.org Subject: Re: tcpdump question X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 21 Mar 2005 18:17:38 -0000 In the last episode (Mar 22), Edwin D. Vinas said: > I've run a tcpdump on my FreeBSD-5.3 machine which is connected via > DSL connection (with fix IP add) passing through a DSL modem. I see > the following weird output, and Im wondering where does the > "192.168.2.1" came from if I disconnected the LAN from my BSD > machine. > > 01:59:04.157465 IP 192.168.2.1 > ALL-SYSTEMS.MCAST.NET: igmp query v2 > 01:59:04.157587 IP 192.168.2.1 > ALL-SYSTEMS.MCAST.NET: igmp query v2 > 01:59:04.318834 IP 192.168.2.1 > RIP2-ROUTERS.MCAST.NET: igmp v2 report RIP2-ROUTERS.MCAST.NET > 01:59:04.318875 IP 192.168.2.1 > 239.255.255.250: igmp v2 report 239.255.255.250 > 01:59:28.374428 IP 192.168.2.1.1900 > 239.255.255.250.1900: UDP, length: 306 Do you maybe have a Windows XP machine on your network? port 1900 is Simple Service Discovery Protocol (SSDP), used by XP to discover routers. The igmp packets are probably doing the same thing. > Another one, is there a GUI to visualize properly the output of > tcpdump? I mean a GUI which can be run as separate X Window > application whose job is to tabulate and display the output of > tcpdump in a human-readable form. ethereal is a good one. You can either run it on tcpdump capture files, or let it capture packets itself. -- Dan Nelson dnelson@allantgroup.com