- 论坛徽章:
- 0
|
使用iptrace抓包如下(任截取一时间)\r\nPacket Number 14031\r\nETH: ====( 60 bytes received on interface en2 )==== 20:07:00.579927920\r\nETH: [ 00:e0:fc:3d:45:83 -> 00:11:25:bd:3c:1b ] type 800 (IP)\r\nIP: < SRC = 10.195.0.68 > \r\nIP: < DST = 172.18.32.78 > (market)\r\nIP: ip_v=4, ip_hl=20, ip_tos=0, ip_len=40, ip_id=1282, ip_off=0\r\nIP: ip_ttl=62, ip_sum=a067, ip_p = 6 (TCP)\r\nTCP: <source port=10235, destination port=80(http) >\r\nTCP: th_seq=683658311, th_ack=0\r\nTCP: th_off=5, flags<SYN>\r\nTCP: th_win=1400, th_sum=b5b1, th_urp=0\r\n\r\nPacket Number 14032\r\nETH: ====( 60 bytes transmitted on interface en2 )==== 20:07:00.579969131\r\nETH: [ 00:11:25:bd:3c:1b -> 00:00:5e:00:01:20 ] type 800 (IP)\r\nIP: < SRC = 172.18.32.78 > (market)\r\nIP: < DST = 10.195.0.68 > \r\nIP: ip_v=4, ip_hl=20, ip_tos=0, ip_len=44, ip_id=25947, ip_off=0 DF\r\nIP: ip_ttl=60, ip_sum=20a, ip_p = 6 (TCP)\r\nTCP: <source port=80(http), destination port=10235 >\r\nTCP: th_seq=3816961830, th_ack=683658312\r\nTCP: th_off=6, flags<SYN | ACK>\r\nTCP: th_win=65535, th_sum=88b3, th_urp=0\r\nTCP: mss 1460\r\n\r\nPacket Number 14033\r\nETH: ====( 60 bytes received on interface en2 )==== 20:07:00.580263558\r\nETH: [ 00:e0:fc:3d:45:83 -> 00:11:25:bd:3c:1b ] type 800 (IP)\r\nIP: < SRC = 10.195.0.68 > \r\nIP: < DST = 172.18.32.78 > (market)\r\nIP: ip_v=4, ip_hl=20, ip_tos=0, ip_len=40, ip_id=1283, ip_off=0\r\nIP: ip_ttl=62, ip_sum=a066, ip_p = 6 (TCP)\r\nTCP: <source port=10235, destination port=80(http) >\r\nTCP: th_seq=683658312, th_ack=3816961831\r\nTCP: th_off=5, flags<FIN | ACK>\r\nTCP: th_win=1400, th_sum=9af7, th_urp=0\r\n\r\nPacket Number 14034\r\nETH: ====( 60 bytes transmitted on interface en2 )==== 20:07:00.580268565\r\nETH: [ 00:11:25:bd:3c:1b -> 00:00:5e:00:01:20 ] type 800 (IP)\r\nIP: < SRC = 172.18.32.78 > (market)\r\nIP: < DST = 10.195.0.68 > \r\nIP: ip_v=4, ip_hl=20, ip_tos=0, ip_len=40, ip_id=25948, ip_off=0 DF\r\nIP: ip_ttl=60, ip_sum=20d, ip_p = 6 (TCP)\r\nTCP: <source port=80(http), destination port=10235 >\r\nTCP: th_seq=3816961831, th_ack=683658313\r\nTCP: th_off=5, flags<ACK>\r\nTCP: th_win=65535, th_sum=a06f, th_urp=0\r\n\r\nPacket Number 14035\r\nETH: ====( 60 bytes received on interface en2 )==== 20:07:00.580271855\r\nETH: [ 00:e0:fc:3d:45:83 -> 00:11:25:bd:3c:1b ] type 800 (IP)\r\nIP: < SRC = 10.195.0.68 > \r\nIP: < DST = 172.18.32.78 > (market)\r\nIP: ip_v=4, ip_hl=20, ip_tos=0, ip_len=40, ip_id=1284, ip_off=0\r\nIP: ip_ttl=62, ip_sum=a065, ip_p = 6 (TCP)\r\nTCP: <source port=10235, destination port=80(http) >\r\nTCP: th_seq=683658312, th_ack=3816961831\r\nTCP: th_off=5, flags<FIN | ACK>\r\nTCP: th_win=1400, th_sum=9af7, th_urp=0\r\n\r\nPacket Number 14036\r\nETH: ====( 60 bytes transmitted on interface en2 )==== 20:07:00.580275395\r\nETH: [ 00:11:25:bd:3c:1b -> 00:00:5e:00:01:20 ] type 800 (IP)\r\nIP: < SRC = 172.18.32.78 > (market)\r\nIP: < DST = 10.195.0.68 > \r\nIP: ip_v=4, ip_hl=20, ip_tos=0, ip_len=40, ip_id=25949, ip_off=0 DF\r\nIP: ip_ttl=60, ip_sum=20c, ip_p = 6 (TCP)\r\nTCP: <source port=80(http), destination port=10235 >\r\nTCP: th_seq=3816961831, th_ack=683658313\r\nTCP: th_off=5, flags<ACK>\r\nTCP: th_win=65535, th_sum=a06f, th_urp=0\r\n\r\nPacket Number 14037\r\nETH: ====( 60 bytes transmitted on interface en2 )==== 20:07:00.580337749\r\nETH: [ 00:11:25:bd:3c:1b -> 00:00:5e:00:01:20 ] type 800 (IP)\r\nIP: < SRC = 172.18.32.78 > (market)\r\nIP: < DST = 10.195.0.68 > \r\nIP: ip_v=4, ip_hl=20, ip_tos=0, ip_len=40, ip_id=25950, ip_off=0 DF\r\nIP: ip_ttl=60, ip_sum=20b, ip_p = 6 (TCP)\r\nTCP: <source port=80(http), destination port=10235 >\r\nTCP: th_seq=3816961831, th_ack=683658313\r\nTCP: th_off=5, flags<FIN | ACK>\r\nTCP: th_win=65535, th_sum=a06e, th_urp=0\r\n\r\nPacket Number 14038\r\nETH: ====( 60 bytes received on interface en2 )==== 20:07:00.580728020\r\nETH: [ 00:e0:fc:3d:45:83 -> 00:11:25:bd:3c:1b ] type 800 (IP)\r\nIP: < SRC = 10.195.0.68 > \r\nIP: < DST = 172.18.32.78 > (market)\r\nIP: ip_v=4, ip_hl=20, ip_tos=0, ip_len=40, ip_id=1285, ip_off=0\r\nIP: ip_ttl=62, ip_sum=a064, ip_p = 6 (TCP)\r\nTCP: <source port=10235, destination port=80(http) >\r\nTCP: th_seq=683658313, th_ack=3816961832\r\nTCP: th_off=5, flags<ACK>\r\nTCP: th_win=1400, th_sum=9af6, th_urp=0\r\n\r\nPacket Number 14039\r\nETH: ====( 60 bytes received on interface en2 )==== 20:07:00.580828012\r\nETH: [ 00:e0:fc:3d:45:83 -> 00:11:25:bd:3c:1b ] type 800 (IP)\r\nIP: < SRC = 10.195.0.68 > \r\nIP: < DST = 172.18.32.78 > (market)\r\nIP: ip_v=4, ip_hl=20, ip_tos=0, ip_len=40, ip_id=1286, ip_off=0\r\nIP: ip_ttl=62, ip_sum=a063, ip_p = 6 (TCP)\r\nTCP: <source port=10235, destination port=80(http) >\r\nTCP: th_seq=683658313, th_ack=0\r\nTCP: th_off=5, flags<RST>\r\nTCP: th_win=1400, th_sum=b5ad, th_urp=0\r\n\r\n目前比较疑惑的地方\r\n1、为什么3步握手时发送SYN标志的客户端10.195.0.68MAC地址与\r\n服务器172.18.32.78返回SYN+ACK的包对应的MAC地址不是一样\r\n使用lscfg -vl 看服务器网卡MAC为001125BD3C1B\r\n网关171.18.32.1 MAC使用arp -a查看为\r\n ? (172.18.32.1) at 0:0:5e:0:1:20 [ethernet] stored in bucket 102\r\n ? (172.18.32.2) at 0:e0:fc:3d:45:83 [ethernet] stored in bucket 103\r\n返回SYN+ACK的MAC地址对应的IP地址却为172.18.32.2\r\n2、为什么3步握手还未结束,客户端10.195.0.68马上发送FIN+SYN的包\r\n\r\n请大家帮忙关注! |
|