06-02-2003 11:18 AM - edited 03-09-2019 03:30 AM
In sensor version 3.x, I used to be able to check the monitoring port by using snoop command. I was told by TAC that 'tcpdump' could be used on 4.x version but they couldn't tell me how to get to the proper place to use the command. Anyone know how to use tcpdump on a IDS sensor utilizing version 4.x?
06-02-2003 08:38 PM
Hi Scott,
Login to the sensor using the service account, then su to root by entering the command ' su ' without the quotes, cd to /usr/sbin. This directory should have the command tcpdump.
To run this command, at the prompt enter the below;
./tcpdump -i eth0 OR eth1 as the case maybe.
Hope this helps.
yatin
06-02-2003 09:10 PM
Forgot to add this,
use the same password for the ' su ' as for the service account.
Yatin
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: