|
All captures
IPv6_NDP.cap (2.1 KB)
Neighbor Discovery Protocol (NDP) uses ICMPv6 to perform duplicate address detection and address resolution. Also includes multicast listener reports. path_MTU_discovery.cap (6.2 KB)
Tracepath is used to determine the MTU of the path between hosts 192.168.0.2 and .1.2. Packet #6 contains an ICMP "fragmentation needed" message, indicating the MTU for that hop is 1400 bytes. 802.1w_rapid_STP.cap (2.2 KB)
Rapid Spanning Tree Protocol BPDUs are received from a Catalyst switch after connecting to a port not configured for PortFast. The port transitions through the blocking and learning states before issuing a topology change notification (packet #30) and transitioning to the forwarding state. PPP_TCP_compression.cap (1.5 KB)
A telnet session is established to 191.1.13.3 across a PPP link performing TCP header compression. The user at 191.1.13.1 logs in with the password "cisco" and terminates the connection. 802.1X.cap (498 bytes)
A wired client authenticates to its switch using 802.1x/EAP and MD5 challenge authentication.
RADIUS.cap (775 bytes)
A RADIUS authentication request is issued from a switch at 10.0.0.1 on behalf of an EAP client. The user authenticates via MD5 challenge with the username "John.McGuirk" and the password "S0cc3r".
TDP.cap (2.8 KB)
P2 and PE2 exchange Tag Distribution Protocol hellos and form an adjacency over TCP port 711. mGRE_ICMP.cap (3.7 KB)
R2 begins sending ICMP traffic to R4, but it currently only has a GRE tunnel open to R1. The first two ICMP requests (packets #1 and #4) are routed through R1 while R2 sends an NHRP request to R1 for R4's spoke address. Once a GRE tunnel is dynamically built between spoke routers R2 and R4, R2 begins routing the ICMP traffic directly to R4. Capture perspective from the R2-R5 link. NHRP_registration.cap (648 bytes)
R2 registers a multipoint GRE tunnel with R1. Capture perspective from the R1-R5 link. MPLS_encapsulation.cap (1.3 KB)
Capture taken from the PE1-P1 link. ICMP traffic between CE1 and CE2 is encapsulated outbound with MPLS label 18. Note that returning traffic is not labeled, due to penultimate hop popping (PHP). LDP_adjacency.cap (5.7 KB)
PE1 and P1 multicast LDP hellos to 224.0.0.2 on UDP port 646. They then establish an adjacency on TCP port 646 and exchange labels. MSDP.cap (4.1 KB)
R2 and R3 become MSDP peers and exchange keepalives. A multicast source 172.16.40.10 begins sending traffic to group 239.123.123.123, and R2 begins sending periodic source active messages to R3. Capture perspective is the R2-R3 link. PIMv2_bootstrap.cap (712 bytes)
Router 1 is the BSR and routers 2 and 3 are candidate RPs with the default priority of 0. R1 collects the RP advertisement unicasts from R2 and R3 and combines them in a bootstrap multicast to all PIM routers. Capture perspective is the R1-R3 link. Auto-RP.cap (726 bytes)
Routers 2 and 3 have been configured as candidate RPs, and multicast RP announcements to 239.0.1.39. Router 1 is the RP. R1 sees the candidate RP announcements from R2 and R3, and designates R3 the RP because it has a higher IP address (3.3.3.3). R1 multicasts the RP mapping to 224.0.1.40. The capture is from the R1-R2 link. PIM-SM_join_prune.cap (3.8 KB)
A host on R4's 172.16.20.0/24 subnet requests to join the 239.123.123.123 group. R4 sends a PIMv2 join message up to the RP (R1). Subsequent join messages are sent every 30 seconds, until R4 determines it no longer has any interested hosts and sends a prune request (packet #45). PIMv1 RP-Reachable messages for the group are also visible from R1. mtrace.cap (238 bytes)
mrinfo_query.cap (182 bytes)
PIM-DM_pruning.cap (10.2 KB)
The multicast source at 172.16.40.10 begins sending traffic to the group 239.123.123.123, and PIM-DM floods the traffic down the tree. R4 has no group members, and prunes itself from the tree. R2 and R3 then realize they have no members, and each prunes itself from the tree. The capture shows R2 receiving the multicast traffic flooded from R1 and subsequently pruning itself every three minutes. PIMv2_hellos.cap (528 bytes)
Routers 1 and 2 exchange PIMv2 hello packets. IGMPv2_query_and_report.cap (438 bytes)
R1 issues IGMPv2 general membership queries to the 172.16.40.0/24 segment every 60 seconds. A host replies to each query reporting it belongs to the multicast group 239.255.255.250. |
Navigation
Armory
Online Toolbox
|