Networking-Blog

My WordPress Blog

Linux – Tcpdump within an ipsec vpn packet

sudo tcpdump -i eth0 -E 3des-cbc:l6h7s4vavpn icmp
this command will let you see all packets coming within the ipsec vpn tunnel of a
network interface


/sbin/iptables –L
this command lists your firewall active rules

tcpdump –i eth0
this command will let you see all packets coming into or out of a network interface,
works on ipsec interfaces as well. Many filter options available

tail –n x /var/log/messages
will display the last x lines of the system log.

ipsec auto –status
This command to get status report from running system. Displays Pluto’s state.
It Includes the list of connections which are currently “added” to Pluto’s internal database;
lists state objects reflecting ISAKMP and IPsec SAs being negotiated or installed.


ipsec look
This command provides brief ipsec status information

ipsec barf
This command provides copious amounts of debugging info for ipsec.

netstat –rn
This command displays your current routing table (in memory)

netstat –an
This command displays your current active ports and their state. Ie: If your firewall is listening on a
certain port or connected on a certain port

Iptables Tcpdump

sudo tcpdump src 85.234.78.202
sudo tcpdump -n host 85.234.78.202
sudo tcpdump -i eth0 -n host 194.62.125.132 -vv
sudo tcpdump -nn -i eth3 host 10.11.254.216 and host 10.11.1.249
sudo tcpdump -nn -i eth2 -E commsvpn host 10.11.254.216 and host 10.11.1.249
sudo tcpdump -nn -i eth2 host 10.11.254.216 and host 213.122.172.146

sudo tcpdump -i eth1 | grep host-1.1.1.1.comms.uk.net
sudo tcpdump -i eth1 | grep 192.168.17.78
sudo tcpdump -i eth1 | grep webmail

sudo tcpdump -i eth0 src 82.109.100.227
sudo tcpdump -i eth1 port 1801
sudo tcpdump -nn -i eth1 port 1801
sudo tcpdump -i eth1.26 host 172.16.30.10 and net 192.168.0.0/16

Packet Sniffing on Destination Ip Address
(80.74.16.249 is a web server, All ip addresses destined for webserver)
sudo tcpdump -i eth0 -vv dst 80.74.16.249 and port 81

sudo tail -f /var/log/messages
sudo cat /var/log/messages | grep DST=25

sudo ifconfig
ping 10.11.1.253 -I eth3

Additional Commands :
tcpdump udp port 2055
!
service ntop status
!
Then, make sure it is listening on the correct port :
netstat -an | grep 2055