tcpdump on openwrt does not output anything












0














I installed openwrt on my router and I'm looking for a way to use tcpdump properly. My internal IP address is 192.168.1.10.



Running tcpdump -i any -l -vvv src 192.168.1.10 and dst not 192.168.1.1 does not output anything and tcpdump -i any src 192.168.1.10 only (many lines of the same kind of logs):



15:17:47.078689 IP 192.168.1.10.43670 > dsldevice.lan.ssh: Flags [.], ack 60065, win 65535, length 0
15:17:47.078744 IP 192.168.1.10.43670 > dsldevice.lan.ssh: Flags [.], ack 60065, win 65535, length 0
15:17:47.079840 IP 192.168.1.10.43670 > dsldevice.lan.ssh: Flags [.], ack 60225, win 65535, length 0


How is it possible? The same happens if any is replaced by any other interface.










share|improve this question







New contributor




xuhozix is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.




















  • What are you expecting to see? Unless you do something or some background process accesses the Internet, nothing being recorded is the expected outcome.
    – Daniel B
    Jan 5 at 15:37










  • I'm running it as I have YouTube videos loading and doing other similar activities
    – xuhozix
    Jan 5 at 15:46






  • 1




    Try throwing in a -n on the command line to disable DNS lookups.
    – davidgo
    2 days ago










  • @davidgo it works! But why?
    – xuhozix
    2 days ago










  • I've never bothered to check, but perceive that the reverse DNS lookups to provide hostnames rather then IPs can take long enough to cause packets to be ignored by tcpdump. (Also why I commented rather then answered.)
    – davidgo
    2 days ago


















0














I installed openwrt on my router and I'm looking for a way to use tcpdump properly. My internal IP address is 192.168.1.10.



Running tcpdump -i any -l -vvv src 192.168.1.10 and dst not 192.168.1.1 does not output anything and tcpdump -i any src 192.168.1.10 only (many lines of the same kind of logs):



15:17:47.078689 IP 192.168.1.10.43670 > dsldevice.lan.ssh: Flags [.], ack 60065, win 65535, length 0
15:17:47.078744 IP 192.168.1.10.43670 > dsldevice.lan.ssh: Flags [.], ack 60065, win 65535, length 0
15:17:47.079840 IP 192.168.1.10.43670 > dsldevice.lan.ssh: Flags [.], ack 60225, win 65535, length 0


How is it possible? The same happens if any is replaced by any other interface.










share|improve this question







New contributor




xuhozix is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.




















  • What are you expecting to see? Unless you do something or some background process accesses the Internet, nothing being recorded is the expected outcome.
    – Daniel B
    Jan 5 at 15:37










  • I'm running it as I have YouTube videos loading and doing other similar activities
    – xuhozix
    Jan 5 at 15:46






  • 1




    Try throwing in a -n on the command line to disable DNS lookups.
    – davidgo
    2 days ago










  • @davidgo it works! But why?
    – xuhozix
    2 days ago










  • I've never bothered to check, but perceive that the reverse DNS lookups to provide hostnames rather then IPs can take long enough to cause packets to be ignored by tcpdump. (Also why I commented rather then answered.)
    – davidgo
    2 days ago
















0












0








0







I installed openwrt on my router and I'm looking for a way to use tcpdump properly. My internal IP address is 192.168.1.10.



Running tcpdump -i any -l -vvv src 192.168.1.10 and dst not 192.168.1.1 does not output anything and tcpdump -i any src 192.168.1.10 only (many lines of the same kind of logs):



15:17:47.078689 IP 192.168.1.10.43670 > dsldevice.lan.ssh: Flags [.], ack 60065, win 65535, length 0
15:17:47.078744 IP 192.168.1.10.43670 > dsldevice.lan.ssh: Flags [.], ack 60065, win 65535, length 0
15:17:47.079840 IP 192.168.1.10.43670 > dsldevice.lan.ssh: Flags [.], ack 60225, win 65535, length 0


How is it possible? The same happens if any is replaced by any other interface.










share|improve this question







New contributor




xuhozix is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.











I installed openwrt on my router and I'm looking for a way to use tcpdump properly. My internal IP address is 192.168.1.10.



Running tcpdump -i any -l -vvv src 192.168.1.10 and dst not 192.168.1.1 does not output anything and tcpdump -i any src 192.168.1.10 only (many lines of the same kind of logs):



15:17:47.078689 IP 192.168.1.10.43670 > dsldevice.lan.ssh: Flags [.], ack 60065, win 65535, length 0
15:17:47.078744 IP 192.168.1.10.43670 > dsldevice.lan.ssh: Flags [.], ack 60065, win 65535, length 0
15:17:47.079840 IP 192.168.1.10.43670 > dsldevice.lan.ssh: Flags [.], ack 60225, win 65535, length 0


How is it possible? The same happens if any is replaced by any other interface.







networking openwrt tcpdump






share|improve this question







New contributor




xuhozix is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.











share|improve this question







New contributor




xuhozix is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.









share|improve this question




share|improve this question






New contributor




xuhozix is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.









asked Jan 5 at 15:30









xuhozixxuhozix

1




1




New contributor




xuhozix is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.





New contributor





xuhozix is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.






xuhozix is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.












  • What are you expecting to see? Unless you do something or some background process accesses the Internet, nothing being recorded is the expected outcome.
    – Daniel B
    Jan 5 at 15:37










  • I'm running it as I have YouTube videos loading and doing other similar activities
    – xuhozix
    Jan 5 at 15:46






  • 1




    Try throwing in a -n on the command line to disable DNS lookups.
    – davidgo
    2 days ago










  • @davidgo it works! But why?
    – xuhozix
    2 days ago










  • I've never bothered to check, but perceive that the reverse DNS lookups to provide hostnames rather then IPs can take long enough to cause packets to be ignored by tcpdump. (Also why I commented rather then answered.)
    – davidgo
    2 days ago




















  • What are you expecting to see? Unless you do something or some background process accesses the Internet, nothing being recorded is the expected outcome.
    – Daniel B
    Jan 5 at 15:37










  • I'm running it as I have YouTube videos loading and doing other similar activities
    – xuhozix
    Jan 5 at 15:46






  • 1




    Try throwing in a -n on the command line to disable DNS lookups.
    – davidgo
    2 days ago










  • @davidgo it works! But why?
    – xuhozix
    2 days ago










  • I've never bothered to check, but perceive that the reverse DNS lookups to provide hostnames rather then IPs can take long enough to cause packets to be ignored by tcpdump. (Also why I commented rather then answered.)
    – davidgo
    2 days ago


















What are you expecting to see? Unless you do something or some background process accesses the Internet, nothing being recorded is the expected outcome.
– Daniel B
Jan 5 at 15:37




What are you expecting to see? Unless you do something or some background process accesses the Internet, nothing being recorded is the expected outcome.
– Daniel B
Jan 5 at 15:37












I'm running it as I have YouTube videos loading and doing other similar activities
– xuhozix
Jan 5 at 15:46




I'm running it as I have YouTube videos loading and doing other similar activities
– xuhozix
Jan 5 at 15:46




1




1




Try throwing in a -n on the command line to disable DNS lookups.
– davidgo
2 days ago




Try throwing in a -n on the command line to disable DNS lookups.
– davidgo
2 days ago












@davidgo it works! But why?
– xuhozix
2 days ago




@davidgo it works! But why?
– xuhozix
2 days ago












I've never bothered to check, but perceive that the reverse DNS lookups to provide hostnames rather then IPs can take long enough to cause packets to be ignored by tcpdump. (Also why I commented rather then answered.)
– davidgo
2 days ago






I've never bothered to check, but perceive that the reverse DNS lookups to provide hostnames rather then IPs can take long enough to cause packets to be ignored by tcpdump. (Also why I commented rather then answered.)
– davidgo
2 days ago












0






active

oldest

votes











Your Answer








StackExchange.ready(function() {
var channelOptions = {
tags: "".split(" "),
id: "3"
};
initTagRenderer("".split(" "), "".split(" "), channelOptions);

StackExchange.using("externalEditor", function() {
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled) {
StackExchange.using("snippets", function() {
createEditor();
});
}
else {
createEditor();
}
});

function createEditor() {
StackExchange.prepareEditor({
heartbeatType: 'answer',
autoActivateHeartbeat: false,
convertImagesToLinks: true,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: 10,
bindNavPrevention: true,
postfix: "",
imageUploader: {
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
},
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
});


}
});






xuhozix is a new contributor. Be nice, and check out our Code of Conduct.










draft saved

draft discarded


















StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fsuperuser.com%2fquestions%2f1390920%2ftcpdump-on-openwrt-does-not-output-anything%23new-answer', 'question_page');
}
);

Post as a guest















Required, but never shown

























0






active

oldest

votes








0






active

oldest

votes









active

oldest

votes






active

oldest

votes








xuhozix is a new contributor. Be nice, and check out our Code of Conduct.










draft saved

draft discarded


















xuhozix is a new contributor. Be nice, and check out our Code of Conduct.













xuhozix is a new contributor. Be nice, and check out our Code of Conduct.












xuhozix is a new contributor. Be nice, and check out our Code of Conduct.
















Thanks for contributing an answer to Super User!


  • Please be sure to answer the question. Provide details and share your research!

But avoid



  • Asking for help, clarification, or responding to other answers.

  • Making statements based on opinion; back them up with references or personal experience.


To learn more, see our tips on writing great answers.





Some of your past answers have not been well-received, and you're in danger of being blocked from answering.


Please pay close attention to the following guidance:


  • Please be sure to answer the question. Provide details and share your research!

But avoid



  • Asking for help, clarification, or responding to other answers.

  • Making statements based on opinion; back them up with references or personal experience.


To learn more, see our tips on writing great answers.




draft saved


draft discarded














StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fsuperuser.com%2fquestions%2f1390920%2ftcpdump-on-openwrt-does-not-output-anything%23new-answer', 'question_page');
}
);

Post as a guest















Required, but never shown





















































Required, but never shown














Required, but never shown












Required, but never shown







Required, but never shown

































Required, but never shown














Required, but never shown












Required, but never shown







Required, but never shown







Popular posts from this blog

How to reconfigure Docker Trusted Registry 2.x.x to use CEPH FS mount instead of NFS and other traditional...

is 'sed' thread safe

How to make a Squid Proxy server?