Ethereal-dev: Re: [Ethereal-dev] Re: [Ethereal-users] New User - How do I cpature/save Cisco D

Note: This archive is from the project's previous web site, ethereal.com. This list is no longer active.

From: Joerg Mayer <jmayer@xxxxxxxxx>
Date: Fri, 21 Jun 2002 01:48:29 +0200
OK, some initial traces from the output of "deb pack det dump".
Setup:

PC(.4)-Eth0 ----192.168.7.0/24--- Eth0-(.111)Cisco2503(.2)-BRI0 ---2.0.0.0/8
The bri is not really connected, I just wanted to have an interface that
was up.

As I currently don't have a X.21 DCE cable, I can't create any serial dumps
right now. I'll try to create some at work on friday, but no promises on that.
The router is configured to create timestamps with millisecond resolution for
debugs. So far it looks like packets are shown including the layer 2 header
when incoming and starting at layer 3 outgoing - and it's ip only of course,
no ipx etc. IIRC, this output varies somewhat with model/software version.

   Ciao
           Jörg

term len 0
Router0#sh ver
Cisco Internetwork Operating System Software 
IOS (tm) 2500 Software (C2500-D-L), Version 11.2(26a), RELEASE SOFTWARE (fc1)
Copyright (c) 1986-2001 by cisco Systems, Inc.
Compiled Thu 07-Jun-01 08:11 by leccese
Image text-base: 0x0302BC14, data-base: 0x00001000

ROM: System Bootstrap, Version 5.2(8a), RELEASE SOFTWARE
BOOTFLASH: 3000 Bootstrap Software (IGS-RXBOOT), Version 10.2(8a), RELEASE SOFTWARE (fc1)

Router0 uptime is 27 minutes
System restarted by power-on at 01:02:07 METDST Fri Jun 21 2002
System image file is "flash:c2500-d-l.112-26a.bin", booted via flash

cisco 2500 (68030) processor (revision D) with 4096K/2048K bytes of memory.
Processor board ID 03218714, with hardware revision 00000000
Bridging software.
X.25 software, Version 2.0, NET2, BFE and GOSIP compliant.
Basic Rate ISDN software, Version 1.0.
1 Ethernet/IEEE 802.3 interface(s)
2 Serial network interface(s)
1 ISDN Basic Rate interface(s)
32K bytes of non-volatile configuration memory.
8192K bytes of processor board System flash (Read ONLY)

Configuration register is 0x2102

Router0#sh run
Building configuration...

Current configuration:
!
! Last configuration change at 01:29:17 METDST Fri Jun 21 2002
! NVRAM config last updated at 01:29:18 METDST Fri Jun 21 2002
!
version 11.2
no service finger
service timestamps debug datetime msec localtime
service timestamps log datetime localtime
service password-encryption
no service udp-small-servers
no service tcp-small-servers
!
hostname Router0
!
!
no ip source-route
no ip domain-lookup
clock timezone MET 1
clock summer-time METDST recurring last Sun Mar 2:00 last Sun Oct 3:00
!
interface Ethernet0
 ip address 192.168.7.111 255.255.255.0
!
interface Serial0
 no ip address
 shutdown
!
interface Serial1
 no ip address
 shutdown
!
interface BRI0
 ip address 2.2.2.2 255.0.0.0
!
ip classless
ip route 0.0.0.0 0.0.0.0 2.2.2.3
!
line con 0
line aux 0
line vty 0 4
 login
!
end

Router0#sh ip int brie
Interface              IP-Address      OK? Method Status                Protocol
BRI0                   2.2.2.2         YES manual up                    up      
Ethernet0              192.168.7.111   YES manual up                    up      

Router0#sh ip route
C    2.0.0.0/8 is directly connected, BRI0
C    192.168.7.0/24 is directly connected, Ethernet0
S*   0.0.0.0/0 [1/0] via 2.2.2.3

!!!!!!!!!!!!!!!! ping from router to 192.168.7.4 !!!!!!!!!!!!!!!!!!!!!!!!!

Jun 21 01:30:28.655: IP: s=192.168.7.111 (local), d=192.168.7.4 (Ethernet0), len 100, sending
Jun 21 01:30:28.659:     ICMP type=8, code=0
00440B70: 45000064 00050000 FF012BD0 C0A8076F  E..d......+P@(.o
00440B80: C0A80704 08007714 00120346 00000000  @(....w....F....
00440B90: 001A03C4 ABCDABCD ABCDABCD ABCDABCD  ...D+M+M+M+M+M+M
00440BA0: ABCDABCD ABCDABCD ABCDABCD ABCDABCD  +M+M+M+M+M+M+M+M
00440BB0: ABCDABCD ABCDABCD ABCDABCD ABCDABCD  +M+M+M+M+M+M+M+M
00440BC0: ABCDABCD ABCDABCD ABCDABCD ABCDABCD  +M+M+M+M+M+M+M+M
00440BD0: ABCDABCD 00                          +M+M.           
Jun 21 01:30:28.695: IP: s=192.168.7.4 (Ethernet0), d=192.168.7.111 (Ethernet0), len 100, rcvd 3
Jun 21 01:30:28.699:     ICMP type=0, code=0
004110E0:              0000 0C923E9A 0060085D        ....>..`.]
004110F0: 76A70800 45000064 371E0000 FE01F5B6  v'..E..d7...~.u6
00411100: C0A80704 C0A8076F 00007F14 00120346  @(..@(.o.......F
00411110: 00000000 001A03C4 ABCDABCD ABCDABCD  .......D+M+M+M+M
00411120: ABCDABCD ABCDABCD ABCDABCD ABCDABCD  +M+M+M+M+M+M+M+M
00411130: ABCDABCD ABCDABCD ABCDABCD ABCDABCD  +M+M+M+M+M+M+M+M
00411140: ABCDABCD ABCDABCD ABCDABCD ABCDABCD  +M+M+M+M+M+M+M+M
00411150: ABCDABCD ABCDABCD EA                 +M+M+M+Mj       
Jun 21 01:30:28.739: IP: s=192.168.7.111 (local), d=192.168.7.4 (Ethernet0), len 100, sending
Jun 21 01:30:28.743:     ICMP type=8, code=0
00440B70: 45000064 00060000 FF012BCF C0A8076F  E..d......+O@(.o
00440B80: C0A80704 080076BB 00130346 00000000  @(....v;...F....
00440B90: 001A041C ABCDABCD ABCDABCD ABCDABCD  ....+M+M+M+M+M+M
00440BA0: ABCDABCD ABCDABCD ABCDABCD ABCDABCD  +M+M+M+M+M+M+M+M
00440BB0: ABCDABCD ABCDABCD ABCDABCD ABCDABCD  +M+M+M+M+M+M+M+M
00440BC0: ABCDABCD ABCDABCD ABCDABCD ABCDABCD  +M+M+M+M+M+M+M+M
00440BD0: ABCDABCD 00                          +M+M.           
Jun 21 01:30:28.775: IP: s=192.168.7.4 (Ethernet0), d=192.168.7.111 (Ethernet0), len 100, rcvd 3
Jun 21 01:30:28.779:     ICMP type=0, code=0
00410A20:                                0000                ..
00410A30: 0C923E9A 0060085D 76A70800 45000064  ..>..`.]v'..E..d
00410A40: 371F0000 FE01F5B5 C0A80704 C0A8076F  7...~.u5@(..@(.o
00410A50: 00007EBB 00130346 00000000 001A041C  ..~;...F........
00410A60: ABCDABCD ABCDABCD ABCDABCD ABCDABCD  +M+M+M+M+M+M+M+M
00410A70: ABCDABCD ABCDABCD ABCDABCD ABCDABCD  +M+M+M+M+M+M+M+M
00410A80: ABCDABCD ABCDABCD ABCDABCD ABCDABCD  +M+M+M+M+M+M+M+M
00410A90: ABCDABCD ABCDABCD ABCDABCD ABCDABCD  +M+M+M+M+M+M+M+M
00410AA0: E6                                   f               
Jun 21 01:30:28.819: IP: s=192.168.7.111 (local), d=192.168.7.4 (Ethernet0), len 100, sending
Jun 21 01:30:28.823:     ICMP type=8, code=0
00440B70: 45000064 00070000 FF012BCE C0A8076F  E..d......+N@(.o
00440B80: C0A80704 0800766A 00140346 00000000  @(....vj...F....
00440B90: 001A046C ABCDABCD ABCDABCD ABCDABCD  ...l+M+M+M+M+M+M
00440BA0: ABCDABCD ABCDABCD ABCDABCD ABCDABCD  +M+M+M+M+M+M+M+M
00440BB0: ABCDABCD ABCDABCD ABCDABCD ABCDABCD  +M+M+M+M+M+M+M+M
00440BC0: ABCDABCD ABCDABCD ABCDABCD ABCDABCD  +M+M+M+M+M+M+M+M
00440BD0: ABCDABCD 00                          +M+M.           
Jun 21 01:30:28.855: IP: s=192.168.7.4 (Ethernet0), d=192.168.7.111 (Ethernet0), len 100, rcvd 3
Jun 21 01:30:28.859:     ICMP type=0, code=0
0040FCB0:                                0000                ..
0040FCC0: 0C923E9A 0060085D 76A70800 45000064  ..>..`.]v'..E..d
0040FCD0: 37200000 FE01F5B4 C0A80704 C0A8076F  7 ..~.u4@(..@(.o
0040FCE0: 00007E6A 00140346 00000000 001A046C  ..~j...F.......l
0040FCF0: ABCDABCD ABCDABCD ABCDABCD ABCDABCD  +M+M+M+M+M+M+M+M
0040FD00: ABCDABCD ABCDABCD ABCDABCD ABCDABCD  +M+M+M+M+M+M+M+M
0040FD10: ABCDABCD ABCDABCD ABCDABCD ABCDABCD  +M+M+M+M+M+M+M+M
0040FD20: ABCDABCD ABCDABCD ABCDABCD ABCDABCD  +M+M+M+M+M+M+M+M
0040FD30: 54                                   T               
Jun 21 01:30:28.899: IP: s=192.168.7.111 (local), d=192.168.7.4 (Ethernet0), len 100, sending
Jun 21 01:30:28.903:     ICMP type=8, code=0
00440B70: 45000064 00080000 FF012BCD C0A8076F  E..d......+M@(.o
00440B80: C0A80704 08007619 00150346 00000000  @(....v....F....
00440B90: 001A04BC ABCDABCD ABCDABCD ABCDABCD  ...<+M+M+M+M+M+M
00440BA0: ABCDABCD ABCDABCD ABCDABCD ABCDABCD  +M+M+M+M+M+M+M+M
00440BB0: ABCDABCD ABCDABCD ABCDABCD ABCDABCD  +M+M+M+M+M+M+M+M
00440BC0: ABCDABCD ABCDABCD ABCDABCD ABCDABCD  +M+M+M+M+M+M+M+M
00440BD0: ABCDABCD 00                          +M+M.           
Jun 21 01:30:28.935: IP: s=192.168.7.4 (Ethernet0), d=192.168.7.111 (Ethernet0), len 100, rcvd 3
Jun 21 01:30:28.939:     ICMP type=0, code=0
0040F600:              0000 0C923E9A 0060085D        ....>..`.]
0040F610: 76A70800 45000064 37210000 FE01F5B3  v'..E..d7!..~.u3
0040F620: C0A80704 C0A8076F 00007E19 00150346  @(..@(.o..~....F
0040F630: 00000000 001A04BC ABCDABCD ABCDABCD  .......<+M+M+M+M
0040F640: ABCDABCD ABCDABCD ABCDABCD ABCDABCD  +M+M+M+M+M+M+M+M
0040F650: ABCDABCD ABCDABCD ABCDABCD ABCDABCD  +M+M+M+M+M+M+M+M
0040F660: ABCDABCD ABCDABCD ABCDABCD ABCDABCD  +M+M+M+M+M+M+M+M
0040F670: ABCDABCD ABCDABCD 52                 +M+M+M+MR       
Jun 21 01:30:28.975: IP: s=192.168.7.111 (local), d=192.168.7.4 (Ethernet0), len 100, sending
Jun 21 01:30:28.979:     ICMP type=8, code=0
00440B70: 45000064 00090000 FF012BCC C0A8076F  E..d......+L@(.o
00440B80: C0A80704 080075CC 00160346 00000000  @(....uL...F....
00440B90: 001A0508 ABCDABCD ABCDABCD ABCDABCD  ....+M+M+M+M+M+M
00440BA0: ABCDABCD ABCDABCD ABCDABCD ABCDABCD  +M+M+M+M+M+M+M+M
00440BB0: ABCDABCD ABCDABCD ABCDABCD ABCDABCD  +M+M+M+M+M+M+M+M
00440BC0: ABCDABCD ABCDABCD ABCDABCD ABCDABCD  +M+M+M+M+M+M+M+M
00440BD0: ABCDABCD 00                          +M+M.           
Jun 21 01:30:29.011: IP: s=192.168.7.4 (Ethernet0), d=192.168.7.111 (Ethernet0), len 100, rcvd 3
Jun 21 01:30:29.015:     ICMP type=0, code=0
0040EF40:                                0000                ..
0040EF50: 0C923E9A 0060085D 76A70800 45000064  ..>..`.]v'..E..d
0040EF60: 37220000 FE01F5B2 C0A80704 C0A8076F  7"..~.u2@(..@(.o
0040EF70: 00007DCC 00160346 00000000 001A0508  ..}L...F........
0040EF80: ABCDABCD ABCDABCD ABCDABCD ABCDABCD  +M+M+M+M+M+M+M+M
0040EF90: ABCDABCD ABCDABCD ABCDABCD ABCDABCD  +M+M+M+M+M+M+M+M
0040EFA0: ABCDABCD ABCDABCD ABCDABCD ABCDABCD  +M+M+M+M+M+M+M+M
0040EFB0: ABCDABCD ABCDABCD ABCDABCD ABCDABCD  +M+M+M+M+M+M+M+M
0040EFC0: 54                                   T               

!!!!!!!!!!!!!!! ping from 192.168.7.4 to 2.3.4.5 !!!!!!!!!!!!!!!!!!!

Jun 21 01:31:26.847: IP: s=192.168.7.4 (Ethernet0), d=2.3.4.5 (BRI0), g=2.3.4.5, len 84, forward
Jun 21 01:31:26.855:     ICMP type=8, code=0
0040E890:              0000 0C923E9A 0060085D        ....>..`.]
0040E8A0: 76A70800 45000054 00004000 3F016DF5  v'..E..T..@.?.mu
0040E8B0: C0A80704 02030405 08000400 B8310100  @(..........81..
0040E8C0: D466123D 63270600 08090A0B 0C0D0E0F  Tf.=c'..........
0040E8D0: 10111213 14151617 18191A1B 1C1D1E1F  ................
0040E8E0: 20212223 24252627 28292A2B 2C2D2E2F   !"#$%&'()*+,-./
0040E8F0: 30313233 34353637 EC                 01234567l       
Jun 21 01:31:26.883: IP: s=192.168.7.4 (Ethernet0), d=2.3.4.5 (BRI0), len 84, encapsulation failed
Jun 21 01:31:26.887:     ICMP type=8, code=0
0040E8A0:          45000054 00004000 3F016DF5      E..T..@.?.mu
0040E8B0: C0A80704 02030405 08000400 B8310100  @(..........81..
0040E8C0: D466123D 63270600 08090A0B 0C0D0E0F  Tf.=c'..........
0040E8D0: 10111213 14151617 18191A1B 1C1D1E1F  ................
0040E8E0: 20212223 24252627 28292A2B 2C2D2E2F   !"#$%&'()*+,-./
0040E8F0: 30313233 34353637 EC                 01234567l       
Jun 21 01:31:27.847: IP: s=192.168.7.4 (Ethernet0), d=2.3.4.5 (BRI0), g=2.3.4.5, len 84, forward
Jun 21 01:31:27.851:     ICMP type=8, code=0
0040E1D0:                                0000                ..
0040E1E0: 0C923E9A 0060085D 76A70800 45000054  ..>..`.]v'..E..T
0040E1F0: 00004000 3F016DF5 C0A80704 02030405  ..@.?.mu@(......
0040E200: 08000E02 B8310200 D566123D 57250600  ....81..Uf.=W%..
0040E210: 08090A0B 0C0D0E0F 10111213 14151617  ................
0040E220: 18191A1B 1C1D1E1F 20212223 24252627  ........ !"#$%&'
0040E230: 28292A2B 2C2D2E2F 30313233 34353637  ()*+,-./01234567
0040E240: BB                                   ;               
Jun 21 01:31:27.887: IP: s=192.168.7.4 (Ethernet0), d=2.3.4.5 (BRI0), len 84, encapsulation failed
Jun 21 01:31:27.891:     ICMP type=8, code=0
0040E1E0:                            45000054              E..T
0040E1F0: 00004000 3F016DF5 C0A80704 02030405  ..@.?.mu@(......
0040E200: 08000E02 B8310200 D566123D 57250600  ....81..Uf.=W%..
0040E210: 08090A0B 0C0D0E0F 10111213 14151617  ................
0040E220: 18191A1B 1C1D1E1F 20212223 24252627  ........ !"#$%&'
0040E230: 28292A2B 2C2D2E2F 30313233 34353637  ()*+,-./01234567
0040E240: BB                                   ;               
Jun 21 01:31:28.855: IP: s=192.168.7.4 (Ethernet0), d=2.3.4.5 (BRI0), g=2.3.4.5, len 84, forward
Jun 21 01:31:28.859:     ICMP type=8, code=0
0040DB20:              0000 0C923E9A 0060085D        ....>..`.]
0040DB30: 76A70800 45000054 00004000 3F016DF5  v'..E..T..@.?.mu
0040DB40: C0A80704 02030405 08002102 B8310300  @(........!.81..
0040DB50: D666123D 42250600 08090A0B 0C0D0E0F  Vf.=B%..........
0040DB60: 10111213 14151617 18191A1B 1C1D1E1F  ................
0040DB70: 20212223 24252627 28292A2B 2C2D2E2F   !"#$%&'()*+,-./
0040DB80: 30313233 34353637 F6                 01234567v       
Jun 21 01:31:28.895: IP: s=192.168.7.4 (Ethernet0), d=2.3.4.5 (BRI0), len 84, encapsulation failed
Jun 21 01:31:28.899:     ICMP type=8, code=0
0040DB30:          45000054 00004000 3F016DF5      E..T..@.?.mu
0040DB40: C0A80704 02030405 08002102 B8310300  @(........!.81..
0040DB50: D666123D 42250600 08090A0B 0C0D0E0F  Vf.=B%..........
0040DB60: 10111213 14151617 18191A1B 1C1D1E1F  ................
0040DB70: 20212223 24252627 28292A2B 2C2D2E2F   !"#$%&'()*+,-./
0040DB80: 30313233 34353637 F6                 01234567v       
Router0#