RE: Tcpdump and 3des packets

From: Andrew Hatfield (andrew@hatfields.com.au)
Date: 09/21/01


Subject: RE: Tcpdump and 3des packets
Date: Fri, 21 Sep 2001 23:09:00 +1000
Message-ID: <F9B05628BAE2414A99980964199E954A01CD92@VOYAGER.brisbane.hatfields.com.au>
From: "Andrew Hatfield" <andrew@hatfields.com.au>
To: "Focus-Linux (E-mail)" <focus-linux@lists.securityfocus.com>

Have you tried ethereal?

That is an excellent network sniffer

  --
  Andrew Hatfield
  Head - Internet Security Division

  Hatfield & Associates Pty. Ltd.
  Phone : +61 7 3849 7155
  Fax : +61 7 3849 6277
  Email : info@hatfields.com.au
  Web : http://www.hatfields.com.au/

> -----Original Message-----
> From: Anthony Baxter [mailto:Anthony.Baxter@draig.co.uk]
> Sent: Monday, 17 September 2001 6:58 PM
> To: focus-linux@securityfocus.com
> Subject: Tcpdump and 3des packets
>
>
>
>
> has anybody been able to use tcpdump to decrypt 3des packets,
> i am trying to
> vpn between freeswan and vpn 1, i need to look at these
> packets but tcpdump
> WILLNOT compile with crypto support
>
> mandrake 8.0
>
> this is my first posting, and i not even sure this is the
> right place to
> post so please forgive me.
>
> What are my options are there other sniffers that can decode 3des ???
>
>
> many thanks
>
> anthony
>



Relevant Pages

  • Re: ntpd fails to synchronize on FreeBSD 6.3-STABLE
    ... 12 packets received by filter ... Then let the tcpdump go for about 15 minutes. ... Firewall on my router/gateway is disabled, ... # shutdown -r now ...
    (freebsd-stable)
  • Re: Should route, but doesnt
    ... > I bought the Netgear box last June. ... > Packets get from the RedHat 7.2 box to my LAN or to the Internet. ... You might find it useful to watch the packets with tcpdump, ... with the private subnets. ...
    (comp.os.linux.networking)
  • Re: Could Not open some sites from Windows Vista and Server 2008 when using FreeBSD as gw
    ... tcpdump: verbose output suppressed, use -v or -vv for full protocol decode ... 433 packets received by filter ... block rules also log the blocked packets -- in this case that should ... Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org ...
    (freebsd-stable)
  • [opensuse] Re: Xen bridge without IP
    ... I can't see the phisycal interface enslaved to the bridge ... Eth0 will be used exclusively for administration tasks and for heartbeat. ... tcpdump: WARNING: eth2: no IPv4 address assigned ... packets received by filter ...
    (SuSE)
  • Re: Why does tcpdump show few packet?
    ... tcpdump: verbose output suppressed, use -v or -vv for full protocol ... 250 packets received by filter ... UP BROADCAST RUNNING PROMISC MULTICAST MTU:1500 Metric:1 ... It seems that my card can't support promiscuous mode because the third line always "UP BROADCAST RUNNING MULTICAST" even I have run tcpdump with root. ...
    (comp.os.linux.networking)