Différences
Ci-dessous, les différences entre deux révisions de la page.
| Les deux révisions précédentesRévision précédente | |||
| 999-archives:140-pppoe:050_sniffs [le 20/06/2025 à 14:47] – supprimée - modification externe (Date inconnue) 127.0.0.1 | 999-archives:140-pppoe:050_sniffs [le 20/06/2025 à 14:47] (Version actuelle) – ↷ Page déplacée de 140pppoe:050_sniffs à 999-archives:140-pppoe:050_sniffs prof | ||
|---|---|---|---|
| Ligne 1: | Ligne 1: | ||
| + | ====== Reniflons un peu... ====== | ||
| + | |||
| + | ===== Un échange ICMP vu de près ===== | ||
| + | |||
| + | La manip qui suit est destinée à éclaircir un peu les idées sur l' | ||
| + | |||
| + | Elle est effectuée sur une machine Linux connectée en PPPoE sur un modem SpeedTouch Home (Accès ADSL). | ||
| + | |||
| + | * L' | ||
| + | |||
| + | [root@gw root]# ifconfig | ||
| + | ... | ||
| + | eth1 Lien encap: | ||
| + | inet adr: | ||
| + | UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1 | ||
| + | ... | ||
| + | ppp0 Lien encap: | ||
| + | inet adr: | ||
| + | UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1492 Metric:1 | ||
| + | ... | ||
| + | |||
| + | Notez que si eth1 dispose de l' | ||
| + | |||
| + | * Deux « sniffers », l'un sur eth1 (couche Ethernet), l' | ||
| + | |||
| + | Voici ce que l'on obtient: | ||
| + | |||
| + | ^ Sur Ethernet (Eth1) | ||
| + | |< | ||
| + | ... | ||
| + | <span class=" | ||
| + | | ||
| + | (Redback_00: | ||
| + | | ||
| + | | ||
| + | Type: PPPoE Session (0x8864) | ||
| + | PPP-over-Ethernet Session | ||
| + | | ||
| + | Type: 1 | ||
| + | Code: Session Data | ||
| + | | ||
| + | | ||
| + | Point-to-Point Protocol | ||
| + | | ||
| + | Internet Protocol, Src Addr: 217.128.147.4 | ||
| + | Dst Addr: 195.25.12.28 | ||
| + | | ||
| + | | ||
| + | | ||
| + | (DSCP 0x00: Default; ECN: 0) | ||
| + | 0000 00..=Differentiated Services | ||
| + | | ||
| + | .... ..0.=ECN-Capable Transport (ECT): 0 | ||
| + | .... ...0=ECN-CE: | ||
| + | Total Length: 84 | ||
| + | | ||
| + | | ||
| + | .1.. = Don't fragment: Set | ||
| + | ..0. = More fragments: Not set | ||
| + | | ||
| + | Time to live: 64 | ||
| + | | ||
| + | | ||
| + | | ||
| + | | ||
| + | Internet Control Message Protocol | ||
| + | Type: 8 (Echo (ping) request) | ||
| + | Code: 0 | ||
| + | | ||
| + | | ||
| + | | ||
| + | Data (56 bytes) | ||
| + | ...</ | ||
| + | Frame 1 (84 on wire, 84 captured) | ||
| + | ... | ||
| + | <span class=" | ||
| + | No link information available | ||
| + | <i>** | ||
| + | ** | ||
| + | ** Au niveau ppp, ce qu'il se passe dessous | ||
| + | ** interpréter, | ||
| + | ** il se croit sur un « vrai » lien PPP | ||
| + | ** parce qu'il écoute sur une interface PPP. | ||
| + | ** Mais en regardant au niveau Ethernet | ||
| + | ** | ||
| + | ** | ||
| + | ** Nous trouvons les informations relatives | ||
| + | ** au protocole PPPoE | ||
| + | **</ | ||
| + | Internet Protocol, Src Addr: 217.128.147.4 | ||
| + | Dst Addr: 195.25.12.28 | ||
| + | | ||
| + | | ||
| + | | ||
| + | (DSCP 0x00: Default; ECN:0) | ||
| + | 0000 00..=Differentiated Services | ||
| + | | ||
| + | .... ..0.=ECN-Capable Transport (ECT): 0 | ||
| + | .... ...0=ECN-CE: | ||
| + | Total Length: 84 | ||
| + | | ||
| + | | ||
| + | .1.. = Don't fragment: Set | ||
| + | ..0. = More fragments: Not set | ||
| + | | ||
| + | Time to live: 64 | ||
| + | | ||
| + | | ||
| + | | ||
| + | | ||
| + | Internet Control Message Protocol | ||
| + | Type: 8 (Echo (ping) request) | ||
| + | Code: 0 | ||
| + | | ||
| + | | ||
| + | | ||
| + | Data (56 bytes) | ||
| + | ...</ | ||
| + | |< | ||
| + | Frame 5 (106 on wire, 106 captured) | ||
| + | ... | ||
| + | <span class=" | ||
| + | | ||
| + | (3Com_50: | ||
| + | | ||
| + | | ||
| + | Type: PPPoE Session (0x8864) | ||
| + | PPP-over-Ethernet Session | ||
| + | | ||
| + | Type: 1 | ||
| + | Code: Session Data | ||
| + | | ||
| + | | ||
| + | Point-to-Point Protocol | ||
| + | | ||
| + | Internet Protocol, Src Addr: 195.25.12.28 | ||
| + | Dst Addr: 217.128.147.4 | ||
| + | | ||
| + | | ||
| + | | ||
| + | (DSCP 0x00: Default; ECN: 0) | ||
| + | 0000 00..=Differentiated Services | ||
| + | | ||
| + | .... ..0.=ECN-Capable Transport (ECT): 0 | ||
| + | .... ...0=ECN-CE: | ||
| + | Total Length: 84 | ||
| + | | ||
| + | | ||
| + | .0.. = Don't fragment: Not set | ||
| + | ..0. = More fragments: Not set | ||
| + | | ||
| + | Time to live: 248 | ||
| + | | ||
| + | | ||
| + | | ||
| + | | ||
| + | Internet Control Message Protocol | ||
| + | Type: 0 (Echo (ping) reply) | ||
| + | Code: 0 Checksum: 0xfb20 (correct) | ||
| + | | ||
| + | | ||
| + | Data (56 bytes) | ||
| + | ... | ||
| + | </ | ||
| + | Frame 2 (84 on wire, 84 captured) | ||
| + | ... | ||
| + | <span class=" | ||
| + | No link information available | ||
| + | <i>** | ||
| + | ** | ||
| + | ** | ||
| + | ** | ||
| + | ** | ||
| + | ** Et pour la réponse | ||
| + | ** c'est la même chose | ||
| + | ** | ||
| + | ** | ||
| + | ** | ||
| + | ** | ||
| + | **</ | ||
| + | Internet Protocol, Src Addr: 195.25.12.28 | ||
| + | Dst Addr: 217.128.147.4 | ||
| + | | ||
| + | | ||
| + | | ||
| + | (DSCP 0x00: Default; ECN: 0) | ||
| + | 0000 00..=Differentiated Services | ||
| + | | ||
| + | .... ..0.=ECN-Capable Transport (ECT): 0 | ||
| + | .... ...0=ECN-CE: | ||
| + | Total Length: 84 | ||
| + | | ||
| + | | ||
| + | .0.. = Don't fragment: Not set | ||
| + | ..0. = More fragments: Not set | ||
| + | | ||
| + | Time to live: 248 | ||
| + | | ||
| + | | ||
| + | | ||
| + | | ||
| + | Internet Control Message Protocol | ||
| + | Type: 0 (Echo (ping) reply) | ||
| + | Code: 0 | ||
| + | | ||
| + | | ||
| + | | ||
| + | Data (56 bytes) | ||
| + | ...</ | ||
| + | |||
| + | Comme il est facile de le constater, on a bien de l'IP qui est transporté au dessus de PPP, lui même au dessus d' | ||
Reniflons un peu...: Dernière modification le: 01/01/1970 à 00:00 par