Ethereal-users: Re: [Ethereal-users] help.......

Note: This archive is from the project's previous web site, ethereal.com. This list is no longer active.

From: Richard Urwin <richard@xxxxxxxxxxxxxxx>
Date: Fri, 5 Sep 2003 15:08:43 +0100
On Friday 05 Sep 2003 8:26 am, Ka K. Lor wrote:
> Hi there,
> I now solve find a way to make my ethereal work.  I find out that by
> connecting to the internet by my phone jack didn't allow me to
> capture any packet....Tell me why...
> Also, the same thing happen to me, when I try to capture filter
> wireless and it didn't capture any things.

http://www.ethereal.com/faq.html#q5.16

> Another question.  What does it mean why I capture package during
> server down and it only show on the first panel window as ping
> request and it has the same thing all the way down.  help me
> understand why it happen like this.....
> Do you know anything about identify three hand shaking in the package
> that my ethereal capture...for example.  after I leave the filter
> blank, and ping google.com with my command dos prompt..  I wasn't
> sure what part really tell me that and what part just junk....
> everything will help...

See the enclosed capture:

$ ping www.google.com

First ping has to find the IP address of www.google.com:

DNS      Standard query A www.google.com
DNS      Standard query response
DNS      Standard query A www.google.com
DNS      Standard query response A 216.239.57.99

The first ping request/response:

ICMP     Echo (ping) request
ICMP     Echo (ping) reply

A reverse lookup of the address that replied, maybe so ping can display 
the name on the screen. It fails:

DNS      Standard query PTR 99.57.239.216.in-addr.arpa
DNS      Standard query response
DNS      Standard query PTR 99.57.239.216.in-addr.arpa
DNS      Standard query response, No such name

Further ping requests and responses

ICMP     Echo (ping) request
ICMP     Echo (ping) reply
 ... 

HTH
-- 
Richard Urwin
    No. Time        Source                Destination           Protocol Info
      1 0.000000    192.168.7.2           192.31.80.30          DNS      Standard query A www.google.com
      2 0.125037    192.31.80.30          192.168.7.2           DNS      Standard query response
      3 0.126389    192.168.7.2           216.239.36.10         DNS      Standard query A www.google.com
      4 0.226069    216.239.36.10         192.168.7.2           DNS      Standard query response A 216.239.57.99
      5 0.227933    192.168.7.2           216.239.57.99         ICMP     Echo (ping) request
      6 0.388807    216.239.57.99         192.168.7.2           ICMP     Echo (ping) reply
      7 0.393935    192.168.7.2           192.100.59.110        DNS      Standard query PTR 99.57.239.216.in-addr.arpa
      8 0.416200    192.100.59.110        192.168.7.2           DNS      Standard query response
      9 0.417235    192.168.7.2           216.239.32.10         DNS      Standard query PTR 99.57.239.216.in-addr.arpa
     10 0.586193    216.239.32.10         192.168.7.2           DNS      Standard query response, No such name
     11 1.234827    192.168.7.2           216.239.57.99         ICMP     Echo (ping) request
     12 1.396495    216.239.57.99         192.168.7.2           ICMP     Echo (ping) reply
     13 2.244956    192.168.7.2           216.239.57.99         ICMP     Echo (ping) request
     14 2.406412    216.239.57.99         192.168.7.2           ICMP     Echo (ping) reply
     15 3.254925    192.168.7.2           216.239.57.99         ICMP     Echo (ping) request
     16 3.415575    216.239.57.99         192.168.7.2           ICMP     Echo (ping) reply
     17 4.264973    192.168.7.2           216.239.57.99         ICMP     Echo (ping) request
     18 4.427209    216.239.57.99         192.168.7.2           ICMP     Echo (ping) reply
     19 5.275480    192.168.7.2           216.239.57.99         ICMP     Echo (ping) request
     20 5.437113    216.239.57.99         192.168.7.2           ICMP     Echo (ping) reply
     21 6.285076    192.168.7.2           216.239.57.99         ICMP     Echo (ping) request
     22 6.447525    216.239.57.99         192.168.7.2           ICMP     Echo (ping) reply
     23 9.075514    192.168.7.2           192.168.7.255         CUPS     ipp://mercury.soronlin.org.uk/printers/Printer (processing)