Ethereal-users: [Ethereal-users] Trouble w/ Capture ipsec Traffic Using SSH Sentinel on WinXP

Note: This archive is from the project's previous web site, ethereal.com. This list is no longer active.

From: "Mike McCandless" <michael@xxxxxxxxxxxx>
Date: Sun, 14 Dec 2003 13:38:56 -0500
I have SSH Sentinel establishing a "road warrior" style connection to a
FreeS/WAN Red Hat box.  This part is working fine.  I can ping the RH box
and see replies.  I also have Samba on the RH box, and have mapped a share
(from Samba) to the WinXP box.

Transferring files from the Samba box seems to be s-l-o-w so, I installed
Ethereal to watch what is happening and see if there are any improvements
that can be made.

When I run the Ethereal capture, I select the SSH Virtual NIC as the
interface.  Problem is, the only traffic I see is a couple of ARP packets.
I know there is more going on.  I'm guessing there is some option that tells
Ethereal to capture/display the AH, ESP, ISAKMP, etc. traffic.

What am I doing wrong?

-----------------------------------------------------------------
Mike McCandless
michael@xxxxxxxxxxxx