- Code: Alles auswählen
No. Time Source Destination Protocol Info
1 07:05:34.593288 0.0.0.0 255.255.255.255 DHCP DHCP Discover - Transaction ID 0xa1ea
2 07:05:34.619124 172.16.201.1 172.16.201.64 DHCP DHCP Offer - Transaction ID 0xa1ea
3 07:05:38.991829 0.0.0.0 255.255.255.255 DHCP DHCP Request - Transaction ID 0xb13a
4 07:05:39.017819 172.16.201.1 172.16.201.64 DHCP DHCP ACK - Transaction ID 0xb13a
5 07:05:39.602460 172.16.201.64 Broadcast ARP Who has 172.16.201.64? Tell 172.16.201.64
....
23 07:18:36.557042 0.0.0.0 255.255.255.255 DHCP DHCP Discover - Transaction ID 0xcc6f
24 07:18:36.582514 172.16.201.1 172.16.201.64 DHCP DHCP Offer - Transaction ID 0xcc6f
25 07:18:44.434680 0.0.0.0 255.255.255.255 DHCP DHCP Discover - Transaction ID 0xe4c5
26 07:18:44.460438 172.16.201.1 172.16.201.64 DHCP DHCP Offer - Transaction ID 0xe4c5
27 07:18:48.434926 0.0.0.0 255.255.255.255 DHCP DHCP Request - Transaction ID 0xf465
28 07:18:48.460943 172.16.201.1 172.16.201.64 DHCP DHCP ACK - Transaction ID 0xf465
29 07:18:49.036359 172.16.201.64 Broadcast ARP Who has 172.16.201.64? Tell 172.16.201.64
30 07:18:49.037643 172.16.201.64 Broadcast ARP Who has 172.16.201.1? Tell 172.16.201.64
31 07:18:49.056893 Cisco_3b:c0:00 172.16.201.64 ARP 172.16.201.1 is at 00:d0:ff:3b:c0:00
32 07:18:49.057440 172.16.201.64 10.0.0.138 TCP 1034 > pptp [SYN] Seq=0 Ack=0 Win=46720 Len=0 MSS=1460
33 07:18:49.076593 10.0.0.138 172.16.201.64 TCP pptp > 1034 [SYN, ACK] Seq=0 Ack=1 Win=5840 Len=0 MSS=1460
34 07:18:49.077983 172.16.201.64 10.0.0.138 TCP 1034 > pptp [ACK] Seq=1 Ack=1 Win=46720 Len=0
35 07:18:49.079009 172.16.201.64 10.0.0.138 PPTP Start-Control-Connection-Request
36 07:18:49.099098 10.0.0.138 172.16.201.64 TCP pptp > 1034 [ACK] Seq=1 Ack=157 Win=5840 Len=0
37 07:18:49.325092 10.0.0.138 172.16.201.64 PPTP Start-Control-Connection-Reply
38 07:18:49.326654 172.16.201.64 10.0.0.138 TCP 1034 > pptp [ACK] Seq=157 Ack=157 Win=46720 Len=0
39 07:18:49.327726 172.16.201.64 10.0.0.138 PPTP Outgoing-Call-Request
40 07:18:49.348137 10.0.0.138 172.16.201.64 TCP pptp > 1034 [ACK] Seq=157 Ack=325 Win=5840 Len=0
41 07:18:49.506300 10.0.0.138 172.16.201.64 PPTP Outgoing-Call-Reply
42 07:18:49.507518 172.16.201.64 10.0.0.138 TCP 1034 > pptp [ACK] Seq=325 Ack=189 Win=46720 Len=0
...
52 07:18:52.444606 172.16.201.64 10.0.0.138 PPP LCP Configuration Request
53 07:18:52.462869 10.0.0.138 172.16.201.64 PPP LCP Configuration Ack
54 07:18:52.464342 172.16.201.64 10.0.0.138 PPP PAP Authenticate-Request
55 07:18:52.483035 10.0.0.138 172.16.201.64 GRE Encapsulated PPP
56 07:18:53.945136 172.16.201.64 10.0.0.138 PPP LCP Echo Request
57 07:18:53.963162 10.0.0.138 172.16.201.64 PPP LCP Echo Reply
58 07:18:54.508565 10.0.0.138 172.16.201.64 PPP PAP Authenticate-Ack
59 07:18:54.508745 10.0.0.138 172.16.201.64 PPP IPCP Configuration Request
60 07:18:54.510978 172.16.201.64 10.0.0.138 PPP IPCP Configuration Request
61 07:18:54.511196 172.16.201.64 10.0.0.138 PPP IPCP Configuration Ack
62 07:18:54.529430 10.0.0.138 172.16.201.64 GRE Encapsulated PPP
63 07:18:54.530572 10.0.0.138 172.16.201.64 GRE Encapsulated PPP
64 07:18:54.531496 10.0.0.138 172.16.201.64 PPP IPCP Configuration Nak
65 07:18:54.532721 172.16.201.64 10.0.0.138 PPP IPCP Configuration Request
66 07:18:54.551449 10.0.0.138 172.16.201.64 GRE Encapsulated PPP
67 07:18:54.565594 10.0.0.138 172.16.201.64 PPP IPCP Configuration Ack
68 07:18:54.875606 83.65.27.212 195.58.160.194 DNS Standard query A ntp1.cs.wisc.edu
69 07:18:54.896214 195.58.160.194 83.65.27.212 DNS Standard query response CNAME caesar.cs.wisc.edu A 128.105.39.11
70 07:18:54.899437 83.65.27.212 128.105.39.11 NTP NTP
71 07:18:55.015459 10.0.0.138 172.16.201.64 GRE Encapsulated PPP
anmerkung: da die einstellungen am anfang noch nicht optimal waren, hats einiger versuche bedurft, die habe ich zt rauseditiert.
das programm, mit dem das geht, heisst ethereal, gibt es (mit unterschiedlicher ausstattung) fuer einige betriebssysteme unter www.ethereal.com wenn man, wie ich hier, die pakete am wan-interface des routers auffangen will, muss man allerdings ein wenig basteln.
anmerkung fuer alle, die den zyair b-2000 v.2 erstmals verwenden: nicht vergessen, das time-setting einzustellen - sonst bekommt er keine oeffentliche ip.