Packet Captures

Sort by new | name | popular

Viewing 1 - 30 of 126

ospf over gre tunnel.cap (8.2 KB)

Packets: 63 Duration: 241s Downloads: 6372

Configured ospf over GRE tunnel in which packets are double tagged with ip header, useful when there is no direct connection between the 2 routers but still we need to run ospf.

connection termination.cap (316 bytes)

Packets: 4 Duration: n/a Downloads: 3625

This is a connection termination packet in which both the server and client sends fin & ack to each other.
For details of how connection is been teared down by both client and server see the link below.
http://www.firewall.cx/networking-topics/protocols/tcp/136-tcp-flag-options.html

  • Categories: None
  • Protocols: IP, TCP

gratuitous arp hsrp.cap (480 bytes)

Packets: 6 Duration: 6s Downloads: 4271

When router take the role of active in hsrp it sends a gratuitous arp in which source mac is 00:00:0c:07:ac:01, the switches update their mac table for the newly learned mac and starts forwarding to that port.

ospf simple password authentication.cap (766 bytes)

Packets: 7 Duration: 60s Downloads: 3381

Simple password authentication in ospf in which we can see password in clear text.
Also the auth type is also specified in the packet which is simple password.
I have also found a very interesting article regarding md5 auth mistakes made by many network engineers the link of which is below.

http://packetlife.net/blog/2010/jun/1/ospfv2-authentication-confusion/

icmp with record route option set.cap (1.2 KB)

Packets: 10 Duration: 2s Downloads: 3378

ping packet with record route option set and IP addresses of all outgoing and incoming interfaces along the path.
In that we can also see position of current pointer.

  • Categories: None
  • Protocols: ICMP, IP

dtls_null.cap (2.2 KB)

Packets: 7 Duration: 7s Downloads: 2169

DTLS handshake with one application data packet.
Authentication with server certificate only.

NULL encryption is used to demonstrate the transmission of "TESTING"

  • Categories: None
  • Protocols: IP, UDP

MSTP_Intra-Region_BPDUs.cap (1.7 KB)

Packets: 10 Duration: 10s Downloads: 3978

MSTP BPDUs captured on an intra-region root port.

00:1f:27:b4:7d:80 - CIST Root (is in another MSTP Region)
00:16:46:b5:8c:80 - CIST Regional Root, Root for Instance 0, 2
00:1e:f7:05:a8:80 - Root for Instance 1

Notice in frame 1 that 00:1e:f7:05:a8:80 uses 32768.00:16:46:b5:8c:80 (Regional Root BID) as bridge ID in the main STP header to make the region appear as a single bridge.

IGMP_V1.cap (2.0 KB)

Packets: 27 Duration: 259s Downloads: 3837

All IGMP V1 requests : Query General, Join specific group

IGMP_V2.cap (1.3 KB)

Packets: 18 Duration: 133s Downloads: 4541

All IGMP V2 requests : Query General, Query specfic group, Join specific group, leave specific group

stun2.cap (102 bytes)

Packets: 1 Duration: n/a Downloads: 2522

Stun (2) Protocol. UDP Holepunching technique.

packet-c.cap (675.0 KB)

Packets: 926 Duration: 13s Downloads: 5245

This is a packet capture from a SonicWall. We were troubleshooting DHCP packet flows. The SonicWall saw the DHCP Discover and Sent an Offer. We never saw the DHCP acknowledgement. In the adjacent core stacked switching we were running "debug ip dhcp server packets" we only saw discover packets from IP phones up to the SonicWall. For some reason the SonicWall could not let any other DHCP packets through or out of it INSIDE (LAN) interface. Even if we put an ANY-ANY ALC for that interface. We ended up having to replace the SonicWall and upload the configuration from the old SonicWall to the new one.

-Slaingod

IPv6_RTSP.cap (15.5 KB)

Packets: 17 Duration: 3s Downloads: 3431

This capture contains IPv6_RTSP packets. Accessed IPv6 enabled RTSP server using 6in4 tunnel.

  • Categories: None
  • Protocols: IP, UDP

OCSP-Not_Implemted.cap (1.1 KB)

Packets: 10 Duration: n/a Downloads: 4842

OCSP-Not_Implemted

OCSP-Revoked.cap (1.8 KB)

Packets: 10 Duration: n/a Downloads: 3763

OCSP (Comodo - FAKE crt Addons-mozilla-org)

OCSP-Good.cap (3.5 KB)

Packets: 14 Duration: 1s Downloads: 4477

OCSP_Good (CRL HTTPS CA Verisign)

traceroute_MPLS.cap (3.3 KB)

Packets: 29 Duration: 3s Downloads: 7976

cm4116_telnet.cap (9.4 KB)

Packets: 113 Duration: 14s Downloads: 6386

Short Telnet session with an Opengear CM4116 used to demonstrate the urgent flag and pointer

HTTP.cap (24.9 KB)

Packets: 40 Duration: n/a Downloads: 10481

Simple HTTP transfer of a PNG image using wget

DHCP_MessageType 10,11,12 and 13.cap (1.9 KB)

Packets: 6 Duration: 13s Downloads: 6675

Access Concentrator/router queries lease for particular IP addresses using message type as "DHCP LEASE QUERY" and gets response as DHCP LEASE ACTIVE,LEASE UNASSIGNED and LEASE UNKNOWN.

Access Concenttrator/Router IP=10.10.39.14
DHCP server IP=10.10.35.33

QinQ.pcap.cap (184 bytes)

Packets: 2 Duration: 2s Downloads: 7563

ARP requests having two vlan IDs attached (QinQ)

iphttps.cap (12.4 KB)

Packets: 83 Duration: 38s Downloads: 7145

IP-HTTPS capture. This is Microsoft's IPv6 inside HTTPS tunneling for DirectAccess.

WCCPv2.pcap.cap (2.8 KB)

Packets: 15 Duration: 27s Downloads: 5063

WCCP communication captures between 7200 Router and a WCCP capable optimization device (In my case it is Riverbed's Stealhead 2050)

LLDP_and_CDP.cap (4.0 KB)

Packets: 12 Duration: 98s Downloads: 7030

LLDP and CDP advertisements sent between two switches, S1 and S2.

TACACS+_encrypted.cap (2.8 KB)

Packets: 34 Duration: 7s Downloads: 6095

TACACS+ authentication and authorization requests as made by a Cisco IOS router upon a user logging in via Telnet.

PPPoE_Dual-Stack_IPv4_IPv6-with_DHCPv6.cap (6.1 KB)

Packets: 65 Duration: 46s Downloads: 7697

Dual-stack PPPoE: IP (IPv4) and IPv6 with DHCPv6

ICMP_over_L2TPv3_Pseudowire.pcap.cap (5.3 KB)

Packets: 38 Duration: 30s Downloads: 6613

ICMP pings from a CE to a second CE via a L2TPv3 pseudowire.

802.1Q_tunneling.cap (5.0 KB)

Packets: 26 Duration: 35s Downloads: 10667

BGP_MP_NLRI.cap (2.9 KB)

Packets: 24 Duration: 60s Downloads: 8709

IPv6 routes are carried as a separate address family inside MP_REACH_NLRI attributes.

TCP_SACK.cap (27.5 KB)

Packets: 39 Duration: n/a Downloads: 15276

A TCP SACK option is included in packets #31, #33, #35, and #37. The missing segment is retransmitted in packet #38.

PPP_EAP.cap (2.5 KB)

Packets: 52 Duration: 52s Downloads: 6676

PPP link negotiation employing EAP MD5 authentication

Viewing 1 - 30 of 126