tcpdump on openwrt does not output anything
I installed openwrt on my router and I'm looking for a way to use tcpdump properly. My internal IP address is 192.168.1.10.
Running tcpdump -i any -l -vvv src 192.168.1.10 and dst not 192.168.1.1
does not output anything and tcpdump -i any src 192.168.1.10
only (many lines of the same kind of logs):
15:17:47.078689 IP 192.168.1.10.43670 > dsldevice.lan.ssh: Flags [.], ack 60065, win 65535, length 0
15:17:47.078744 IP 192.168.1.10.43670 > dsldevice.lan.ssh: Flags [.], ack 60065, win 65535, length 0
15:17:47.079840 IP 192.168.1.10.43670 > dsldevice.lan.ssh: Flags [.], ack 60225, win 65535, length 0
How is it possible? The same happens if any
is replaced by any other interface.
networking openwrt tcpdump
New contributor
|
show 1 more comment
I installed openwrt on my router and I'm looking for a way to use tcpdump properly. My internal IP address is 192.168.1.10.
Running tcpdump -i any -l -vvv src 192.168.1.10 and dst not 192.168.1.1
does not output anything and tcpdump -i any src 192.168.1.10
only (many lines of the same kind of logs):
15:17:47.078689 IP 192.168.1.10.43670 > dsldevice.lan.ssh: Flags [.], ack 60065, win 65535, length 0
15:17:47.078744 IP 192.168.1.10.43670 > dsldevice.lan.ssh: Flags [.], ack 60065, win 65535, length 0
15:17:47.079840 IP 192.168.1.10.43670 > dsldevice.lan.ssh: Flags [.], ack 60225, win 65535, length 0
How is it possible? The same happens if any
is replaced by any other interface.
networking openwrt tcpdump
New contributor
What are you expecting to see? Unless you do something or some background process accesses the Internet, nothing being recorded is the expected outcome.
– Daniel B
Jan 5 at 15:37
I'm running it as I have YouTube videos loading and doing other similar activities
– xuhozix
Jan 5 at 15:46
1
Try throwing in a -n on the command line to disable DNS lookups.
– davidgo
2 days ago
@davidgo it works! But why?
– xuhozix
2 days ago
I've never bothered to check, but perceive that the reverse DNS lookups to provide hostnames rather then IPs can take long enough to cause packets to be ignored by tcpdump. (Also why I commented rather then answered.)
– davidgo
2 days ago
|
show 1 more comment
I installed openwrt on my router and I'm looking for a way to use tcpdump properly. My internal IP address is 192.168.1.10.
Running tcpdump -i any -l -vvv src 192.168.1.10 and dst not 192.168.1.1
does not output anything and tcpdump -i any src 192.168.1.10
only (many lines of the same kind of logs):
15:17:47.078689 IP 192.168.1.10.43670 > dsldevice.lan.ssh: Flags [.], ack 60065, win 65535, length 0
15:17:47.078744 IP 192.168.1.10.43670 > dsldevice.lan.ssh: Flags [.], ack 60065, win 65535, length 0
15:17:47.079840 IP 192.168.1.10.43670 > dsldevice.lan.ssh: Flags [.], ack 60225, win 65535, length 0
How is it possible? The same happens if any
is replaced by any other interface.
networking openwrt tcpdump
New contributor
I installed openwrt on my router and I'm looking for a way to use tcpdump properly. My internal IP address is 192.168.1.10.
Running tcpdump -i any -l -vvv src 192.168.1.10 and dst not 192.168.1.1
does not output anything and tcpdump -i any src 192.168.1.10
only (many lines of the same kind of logs):
15:17:47.078689 IP 192.168.1.10.43670 > dsldevice.lan.ssh: Flags [.], ack 60065, win 65535, length 0
15:17:47.078744 IP 192.168.1.10.43670 > dsldevice.lan.ssh: Flags [.], ack 60065, win 65535, length 0
15:17:47.079840 IP 192.168.1.10.43670 > dsldevice.lan.ssh: Flags [.], ack 60225, win 65535, length 0
How is it possible? The same happens if any
is replaced by any other interface.
networking openwrt tcpdump
networking openwrt tcpdump
New contributor
New contributor
New contributor
asked Jan 5 at 15:30
xuhozixxuhozix
1
1
New contributor
New contributor
What are you expecting to see? Unless you do something or some background process accesses the Internet, nothing being recorded is the expected outcome.
– Daniel B
Jan 5 at 15:37
I'm running it as I have YouTube videos loading and doing other similar activities
– xuhozix
Jan 5 at 15:46
1
Try throwing in a -n on the command line to disable DNS lookups.
– davidgo
2 days ago
@davidgo it works! But why?
– xuhozix
2 days ago
I've never bothered to check, but perceive that the reverse DNS lookups to provide hostnames rather then IPs can take long enough to cause packets to be ignored by tcpdump. (Also why I commented rather then answered.)
– davidgo
2 days ago
|
show 1 more comment
What are you expecting to see? Unless you do something or some background process accesses the Internet, nothing being recorded is the expected outcome.
– Daniel B
Jan 5 at 15:37
I'm running it as I have YouTube videos loading and doing other similar activities
– xuhozix
Jan 5 at 15:46
1
Try throwing in a -n on the command line to disable DNS lookups.
– davidgo
2 days ago
@davidgo it works! But why?
– xuhozix
2 days ago
I've never bothered to check, but perceive that the reverse DNS lookups to provide hostnames rather then IPs can take long enough to cause packets to be ignored by tcpdump. (Also why I commented rather then answered.)
– davidgo
2 days ago
What are you expecting to see? Unless you do something or some background process accesses the Internet, nothing being recorded is the expected outcome.
– Daniel B
Jan 5 at 15:37
What are you expecting to see? Unless you do something or some background process accesses the Internet, nothing being recorded is the expected outcome.
– Daniel B
Jan 5 at 15:37
I'm running it as I have YouTube videos loading and doing other similar activities
– xuhozix
Jan 5 at 15:46
I'm running it as I have YouTube videos loading and doing other similar activities
– xuhozix
Jan 5 at 15:46
1
1
Try throwing in a -n on the command line to disable DNS lookups.
– davidgo
2 days ago
Try throwing in a -n on the command line to disable DNS lookups.
– davidgo
2 days ago
@davidgo it works! But why?
– xuhozix
2 days ago
@davidgo it works! But why?
– xuhozix
2 days ago
I've never bothered to check, but perceive that the reverse DNS lookups to provide hostnames rather then IPs can take long enough to cause packets to be ignored by tcpdump. (Also why I commented rather then answered.)
– davidgo
2 days ago
I've never bothered to check, but perceive that the reverse DNS lookups to provide hostnames rather then IPs can take long enough to cause packets to be ignored by tcpdump. (Also why I commented rather then answered.)
– davidgo
2 days ago
|
show 1 more comment
0
active
oldest
votes
Your Answer
StackExchange.ready(function() {
var channelOptions = {
tags: "".split(" "),
id: "3"
};
initTagRenderer("".split(" "), "".split(" "), channelOptions);
StackExchange.using("externalEditor", function() {
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled) {
StackExchange.using("snippets", function() {
createEditor();
});
}
else {
createEditor();
}
});
function createEditor() {
StackExchange.prepareEditor({
heartbeatType: 'answer',
autoActivateHeartbeat: false,
convertImagesToLinks: true,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: 10,
bindNavPrevention: true,
postfix: "",
imageUploader: {
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
},
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
});
}
});
xuhozix is a new contributor. Be nice, and check out our Code of Conduct.
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fsuperuser.com%2fquestions%2f1390920%2ftcpdump-on-openwrt-does-not-output-anything%23new-answer', 'question_page');
}
);
Post as a guest
Required, but never shown
0
active
oldest
votes
0
active
oldest
votes
active
oldest
votes
active
oldest
votes
xuhozix is a new contributor. Be nice, and check out our Code of Conduct.
xuhozix is a new contributor. Be nice, and check out our Code of Conduct.
xuhozix is a new contributor. Be nice, and check out our Code of Conduct.
xuhozix is a new contributor. Be nice, and check out our Code of Conduct.
Thanks for contributing an answer to Super User!
- Please be sure to answer the question. Provide details and share your research!
But avoid …
- Asking for help, clarification, or responding to other answers.
- Making statements based on opinion; back them up with references or personal experience.
To learn more, see our tips on writing great answers.
Some of your past answers have not been well-received, and you're in danger of being blocked from answering.
Please pay close attention to the following guidance:
- Please be sure to answer the question. Provide details and share your research!
But avoid …
- Asking for help, clarification, or responding to other answers.
- Making statements based on opinion; back them up with references or personal experience.
To learn more, see our tips on writing great answers.
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fsuperuser.com%2fquestions%2f1390920%2ftcpdump-on-openwrt-does-not-output-anything%23new-answer', 'question_page');
}
);
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
What are you expecting to see? Unless you do something or some background process accesses the Internet, nothing being recorded is the expected outcome.
– Daniel B
Jan 5 at 15:37
I'm running it as I have YouTube videos loading and doing other similar activities
– xuhozix
Jan 5 at 15:46
1
Try throwing in a -n on the command line to disable DNS lookups.
– davidgo
2 days ago
@davidgo it works! But why?
– xuhozix
2 days ago
I've never bothered to check, but perceive that the reverse DNS lookups to provide hostnames rather then IPs can take long enough to cause packets to be ignored by tcpdump. (Also why I commented rather then answered.)
– davidgo
2 days ago