- 论坛徽章:
- 0
|
这是我在VS上的监测
[root@localhost ~]# tcpdump -i eth1 -nnn 'tcp and src port 21'
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on eth1, link-type EN10MB (Ethernet), capture size 96 bytes
16:18:28.886559 IP 192.168.0.24.21 > 192.168.0.188.1147: S 1668927168:1668927168(0) ack 1886514398 win 5840 <mss 1460,nop,nop,sackOK>
16:18:28.888245 IP 192.168.0.24.21 > 192.168.0.188.1147: P 1:29(2 ack 1 win 5840
16:18:28.888468 IP 192.168.0.24.21 > 192.168.0.188.1147: F 29:29(0) ack 1 win 5840
16:18:35.073192 IP 192.168.0.24.21 > 192.168.0.188.1148: S 1659958277:1659958277(0) ack 719216676 win 5840 <mss 1460,nop,nop,sackOK>
16:18:35.074975 IP 192.168.0.24.21 > 192.168.0.188.1148: P 1:29(2 ack 1 win 5840
16:18:35.075344 IP 192.168.0.24.21 > 192.168.0.188.1148: F 29:29(0) ack 1 win 5840
16:18:37.697668 IP 192.168.0.24.21 > 192.168.0.188.1149: S 1672675050:1672675050(0) ack 3575207895 win 5840 <mss 1460,nop,nop,sackOK>
16:18:37.699945 IP 192.168.0.24.21 > 192.168.0.188.1149: P 1:29(2 ack 1 win 5840
16:18:37.700375 IP 192.168.0.24.21 > 192.168.0.188.1149: F 29:29(0) ack 1 win 5840
[root@localhost netfilter]# tcpdump -i eth0 -nnn 'tcp and port 21'
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on eth0, link-type EN10MB (Ethernet), capture size 96 bytes
16:18:28.886449 IP 192.168.0.188.1147 > 10.0.0.13.21: S 1886514397:1886514397(0) win 65535 <mss 1460,nop,nop,sackOK>
16:18:28.886545 IP 10.0.0.13.21 > 192.168.0.188.1147: S 1668927168:1668927168(0) ack 1886514398 win 5840 <mss 1460,nop,nop,sackOK>
16:18:28.886658 IP 192.168.0.188.1147 > 10.0.0.13.21: . ack 1 win 65535
16:18:28.888215 IP 10.0.0.13.21 > 192.168.0.188.1147: P 1:29(2 ack 1 win 5840
16:18:28.888453 IP 10.0.0.13.21 > 192.168.0.188.1147: F 29:29(0) ack 1 win 5840
16:18:28.888576 IP 192.168.0.188.1147 > 10.0.0.13.21: . ack 30 win 65507
16:18:28.890920 IP 192.168.0.188.1147 > 10.0.0.13.21: R 1:1(0) ack 30 win 0
16:18:35.073046 IP 192.168.0.188.1148 > 10.0.0.12.21: S 719216675:719216675(0) win 65535 <mss 1460,nop,nop,sackOK>
16:18:35.073177 IP 10.0.0.12.21 > 192.168.0.188.1148: S 1659958277:1659958277(0) ack 719216676 win 5840 <mss 1460,nop,nop,sackOK>
16:18:35.073327 IP 192.168.0.188.1148 > 10.0.0.12.21: . ack 1 win 65535
16:18:35.074962 IP 10.0.0.12.21 > 192.168.0.188.1148: P 1:29(2 ack 1 win 5840
16:18:35.075332 IP 10.0.0.12.21 > 192.168.0.188.1148: F 29:29(0) ack 1 win 5840
16:18:35.075460 IP 192.168.0.188.1148 > 10.0.0.12.21: . ack 30 win 65507
16:18:35.077574 IP 192.168.0.188.1148 > 10.0.0.12.21: R 1:1(0) ack 30 win 0
16:18:37.697493 IP 192.168.0.188.1149 > 10.0.0.11.21: S 3575207894:3575207894(0) win 65535 <mss 1460,nop,nop,sackOK>
16:18:37.697652 IP 10.0.0.11.21 > 192.168.0.188.1149: S 1672675050:1672675050(0) ack 3575207895 win 5840 <mss 1460,nop,nop,sackOK>
16:18:37.697780 IP 192.168.0.188.1149 > 10.0.0.11.21: . ack 1 win 65535
16:18:37.699922 IP 10.0.0.11.21 > 192.168.0.188.1149: P 1:29(2 ack 1 win 5840
16:18:37.700363 IP 10.0.0.11.21 > 192.168.0.188.1149: F 29:29(0) ack 1 win 5840
16:18:37.700476 IP 192.168.0.188.1149 > 10.0.0.11.21: . ack 30 win 65507
16:18:37.702508 IP 192.168.0.188.1149 > 10.0.0.11.21: R 1:1(0) ack 30 win 0
希望高手重新看一下 |
|