tcpdump on openwrt does not output anything












0















I installed openwrt on my router and I'm looking for a way to use tcpdump properly. My internal IP address is 192.168.1.10.



Running tcpdump -i any -l -vvv src 192.168.1.10 and dst not 192.168.1.1 does not output anything and tcpdump -i any src 192.168.1.10 only (many lines of the same kind of logs):



15:17:47.078689 IP 192.168.1.10.43670 > dsldevice.lan.ssh: Flags [.], ack 60065, win 65535, length 0
15:17:47.078744 IP 192.168.1.10.43670 > dsldevice.lan.ssh: Flags [.], ack 60065, win 65535, length 0
15:17:47.079840 IP 192.168.1.10.43670 > dsldevice.lan.ssh: Flags [.], ack 60225, win 65535, length 0


How is it possible? The same happens if any is replaced by any other interface.










share|improve this question























  • What are you expecting to see? Unless you do something or some background process accesses the Internet, nothing being recorded is the expected outcome.

    – Daniel B
    Jan 5 at 15:37











  • I'm running it as I have YouTube videos loading and doing other similar activities

    – xuhozix
    Jan 5 at 15:46






  • 1





    Try throwing in a -n on the command line to disable DNS lookups.

    – davidgo
    Jan 5 at 21:23











  • @davidgo it works! But why?

    – xuhozix
    Jan 5 at 23:56











  • I've never bothered to check, but perceive that the reverse DNS lookups to provide hostnames rather then IPs can take long enough to cause packets to be ignored by tcpdump. (Also why I commented rather then answered.)

    – davidgo
    Jan 6 at 0:07


















0















I installed openwrt on my router and I'm looking for a way to use tcpdump properly. My internal IP address is 192.168.1.10.



Running tcpdump -i any -l -vvv src 192.168.1.10 and dst not 192.168.1.1 does not output anything and tcpdump -i any src 192.168.1.10 only (many lines of the same kind of logs):



15:17:47.078689 IP 192.168.1.10.43670 > dsldevice.lan.ssh: Flags [.], ack 60065, win 65535, length 0
15:17:47.078744 IP 192.168.1.10.43670 > dsldevice.lan.ssh: Flags [.], ack 60065, win 65535, length 0
15:17:47.079840 IP 192.168.1.10.43670 > dsldevice.lan.ssh: Flags [.], ack 60225, win 65535, length 0


How is it possible? The same happens if any is replaced by any other interface.










share|improve this question























  • What are you expecting to see? Unless you do something or some background process accesses the Internet, nothing being recorded is the expected outcome.

    – Daniel B
    Jan 5 at 15:37











  • I'm running it as I have YouTube videos loading and doing other similar activities

    – xuhozix
    Jan 5 at 15:46






  • 1





    Try throwing in a -n on the command line to disable DNS lookups.

    – davidgo
    Jan 5 at 21:23











  • @davidgo it works! But why?

    – xuhozix
    Jan 5 at 23:56











  • I've never bothered to check, but perceive that the reverse DNS lookups to provide hostnames rather then IPs can take long enough to cause packets to be ignored by tcpdump. (Also why I commented rather then answered.)

    – davidgo
    Jan 6 at 0:07
















0












0








0








I installed openwrt on my router and I'm looking for a way to use tcpdump properly. My internal IP address is 192.168.1.10.



Running tcpdump -i any -l -vvv src 192.168.1.10 and dst not 192.168.1.1 does not output anything and tcpdump -i any src 192.168.1.10 only (many lines of the same kind of logs):



15:17:47.078689 IP 192.168.1.10.43670 > dsldevice.lan.ssh: Flags [.], ack 60065, win 65535, length 0
15:17:47.078744 IP 192.168.1.10.43670 > dsldevice.lan.ssh: Flags [.], ack 60065, win 65535, length 0
15:17:47.079840 IP 192.168.1.10.43670 > dsldevice.lan.ssh: Flags [.], ack 60225, win 65535, length 0


How is it possible? The same happens if any is replaced by any other interface.










share|improve this question














I installed openwrt on my router and I'm looking for a way to use tcpdump properly. My internal IP address is 192.168.1.10.



Running tcpdump -i any -l -vvv src 192.168.1.10 and dst not 192.168.1.1 does not output anything and tcpdump -i any src 192.168.1.10 only (many lines of the same kind of logs):



15:17:47.078689 IP 192.168.1.10.43670 > dsldevice.lan.ssh: Flags [.], ack 60065, win 65535, length 0
15:17:47.078744 IP 192.168.1.10.43670 > dsldevice.lan.ssh: Flags [.], ack 60065, win 65535, length 0
15:17:47.079840 IP 192.168.1.10.43670 > dsldevice.lan.ssh: Flags [.], ack 60225, win 65535, length 0


How is it possible? The same happens if any is replaced by any other interface.







networking openwrt tcpdump






share|improve this question













share|improve this question











share|improve this question




share|improve this question










asked Jan 5 at 15:30









xuhozixxuhozix

1




1













  • What are you expecting to see? Unless you do something or some background process accesses the Internet, nothing being recorded is the expected outcome.

    – Daniel B
    Jan 5 at 15:37











  • I'm running it as I have YouTube videos loading and doing other similar activities

    – xuhozix
    Jan 5 at 15:46






  • 1





    Try throwing in a -n on the command line to disable DNS lookups.

    – davidgo
    Jan 5 at 21:23











  • @davidgo it works! But why?

    – xuhozix
    Jan 5 at 23:56











  • I've never bothered to check, but perceive that the reverse DNS lookups to provide hostnames rather then IPs can take long enough to cause packets to be ignored by tcpdump. (Also why I commented rather then answered.)

    – davidgo
    Jan 6 at 0:07





















  • What are you expecting to see? Unless you do something or some background process accesses the Internet, nothing being recorded is the expected outcome.

    – Daniel B
    Jan 5 at 15:37











  • I'm running it as I have YouTube videos loading and doing other similar activities

    – xuhozix
    Jan 5 at 15:46






  • 1





    Try throwing in a -n on the command line to disable DNS lookups.

    – davidgo
    Jan 5 at 21:23











  • @davidgo it works! But why?

    – xuhozix
    Jan 5 at 23:56











  • I've never bothered to check, but perceive that the reverse DNS lookups to provide hostnames rather then IPs can take long enough to cause packets to be ignored by tcpdump. (Also why I commented rather then answered.)

    – davidgo
    Jan 6 at 0:07



















What are you expecting to see? Unless you do something or some background process accesses the Internet, nothing being recorded is the expected outcome.

– Daniel B
Jan 5 at 15:37





What are you expecting to see? Unless you do something or some background process accesses the Internet, nothing being recorded is the expected outcome.

– Daniel B
Jan 5 at 15:37













I'm running it as I have YouTube videos loading and doing other similar activities

– xuhozix
Jan 5 at 15:46





I'm running it as I have YouTube videos loading and doing other similar activities

– xuhozix
Jan 5 at 15:46




1




1





Try throwing in a -n on the command line to disable DNS lookups.

– davidgo
Jan 5 at 21:23





Try throwing in a -n on the command line to disable DNS lookups.

– davidgo
Jan 5 at 21:23













@davidgo it works! But why?

– xuhozix
Jan 5 at 23:56





@davidgo it works! But why?

– xuhozix
Jan 5 at 23:56













I've never bothered to check, but perceive that the reverse DNS lookups to provide hostnames rather then IPs can take long enough to cause packets to be ignored by tcpdump. (Also why I commented rather then answered.)

– davidgo
Jan 6 at 0:07







I've never bothered to check, but perceive that the reverse DNS lookups to provide hostnames rather then IPs can take long enough to cause packets to be ignored by tcpdump. (Also why I commented rather then answered.)

– davidgo
Jan 6 at 0:07












0






active

oldest

votes











Your Answer








StackExchange.ready(function() {
var channelOptions = {
tags: "".split(" "),
id: "3"
};
initTagRenderer("".split(" "), "".split(" "), channelOptions);

StackExchange.using("externalEditor", function() {
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled) {
StackExchange.using("snippets", function() {
createEditor();
});
}
else {
createEditor();
}
});

function createEditor() {
StackExchange.prepareEditor({
heartbeatType: 'answer',
autoActivateHeartbeat: false,
convertImagesToLinks: true,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: 10,
bindNavPrevention: true,
postfix: "",
imageUploader: {
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
},
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
});


}
});














draft saved

draft discarded


















StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fsuperuser.com%2fquestions%2f1390920%2ftcpdump-on-openwrt-does-not-output-anything%23new-answer', 'question_page');
}
);

Post as a guest















Required, but never shown

























0






active

oldest

votes








0






active

oldest

votes









active

oldest

votes






active

oldest

votes
















draft saved

draft discarded




















































Thanks for contributing an answer to Super User!


  • Please be sure to answer the question. Provide details and share your research!

But avoid



  • Asking for help, clarification, or responding to other answers.

  • Making statements based on opinion; back them up with references or personal experience.


To learn more, see our tips on writing great answers.




draft saved


draft discarded














StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fsuperuser.com%2fquestions%2f1390920%2ftcpdump-on-openwrt-does-not-output-anything%23new-answer', 'question_page');
}
);

Post as a guest















Required, but never shown





















































Required, but never shown














Required, but never shown












Required, but never shown







Required, but never shown

































Required, but never shown














Required, but never shown












Required, but never shown







Required, but never shown







Popular posts from this blog

Plaza Victoria

In PowerPoint, is there a keyboard shortcut for bulleted / numbered list?

How to put 3 figures in Latex with 2 figures side by side and 1 below these side by side images but in...