Solved

Debug packet INT SRC MASK output confusion

Posted on 2004-09-09
1
182 Views
Last Modified: 2012-06-21
By using the debug command how can I tell if traffic was passed or rejected from a specific IP or range.  For instance here is the output I recieved in my test.  I know that it was blocked but what in the output will confirm that for me?

--------- PACKET ---------

-- IP --
Source ==>     Dest

        ver = 0x4       hlen = 0x5      tos = 0x0       tlen = 0x30
        id = 0x6321     flags = 0x40    frag off=0x0
        ttl = 0x7e      proto=0x6       chksum = 0xb494

        -- TCP --
                source port = 0x7b0     dest port = 0x17syn

                seq = 0x166cf6da
                ack = 0x0
                hlen = 0x7              window = 0xffff
                checksum = 0x88ff       urg = 0x0
tcp options:
                        0x2     0x4     0x5     0xb4    0x1     0x1     0x4
0x2
--------- END OF PACKET ---------

--------- PACKET ---------

-- IP --
Source ==>     Dest

        ver = 0x4       hlen = 0x5      tos = 0x0       tlen = 0x30
        id = 0x6322     flags = 0x40    frag off=0x0
        ttl = 0x7e      proto=0x6       chksum = 0xb493

        -- TCP --
                source port = 0x7b0     dest port = 0x17syn

                seq = 0x166cf6da
                ack = 0x0
                hlen = 0x7              window = 0xffff
                checksum = 0x88ff       urg = 0x0
tcp options:
                        0x2     0x4     0x5     0xb4    0x1     0x1     0x4
0x2
--------- END OF PACKET ---------

--------- PACKET ---------

-- IP --
Source ==>     Dest

        ver = 0x4       hlen = 0x5      tos = 0x0       tlen = 0x30
        id = 0x6323     flags = 0x40    frag off=0x0
        ttl = 0x7e      proto=0x6       chksum = 0xb492

        -- TCP --
                source port = 0x7b0     dest port = 0x17syn

                seq = 0x166cf6da
                ack = 0x0
                hlen = 0x7              window = 0xffff
                checksum = 0x88ff       urg = 0x0
tcp options:
                        0x2     0x4     0x5     0xb4    0x1     0x1     0x4
0x2
--------- END OF PACKET ---------


Thanks,

Sunny
0
Comment
Question by:sunnyd24
1 Comment
 
LVL 23

Accepted Solution

by:
Tim Holman earned 500 total points
Comment Utility
It doesn't.  This is only a packet capture.  You could compare this to what you see blocked in the fw logs ?
0

Featured Post

Do You Know the 4 Main Threat Actor Types?

Do you know the main threat actor types? Most attackers fall into one of four categories, each with their own favored tactics, techniques, and procedures.

Join & Write a Comment

Do you have a windows based Checkpoint SmartCenter for centralized Checkpoint management?  Have you ever backed up the firewall policy residing on the SmartCenter?  If you have then you know the hassles of connecting to the server, doing an upgrade_…
This article offers some helpful and general tips for safe browsing and online shopping. It offers simple and manageable procedures that help to ensure the safety of one's personal information and the security of any devices.
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
You have products, that come in variants and want to set different prices for them? Watch this micro tutorial that describes how to configure prices for Magento super attributes. Assigning simple products to configurable: We assigned simple products…

728 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now