Re: tcpdump broken after rh9 2.4.20-27.9 kernel upgrade

From: Harry Hoffman (hhoffman_at_ip-solutions.net)
Date: 12/27/03

  • Next message: Robert Brown: "Re: tcpdump broken after rh9 2.4.20-27.9 kernel upgrade"
    To: redhat-list@redhat.com
    Date: Fri, 26 Dec 2003 19:26:45 -0500
    
    

    Hmm,

    I updated via up2date and my tcpdump works fine. Also, my old kernel wasn't
    removed automatically...
    I'm not quite sure that this really helps but at the very least you know that
    different things are being seen :-(

    Do you have other systems that this has happened to or is this the only one?

    HTH,
    Harry

    Quoting Robert Brown <eli@typhoon.xnet.com>:

    *> Robert Brown writes:
    *> > I use tcpdump as a component of an network monitoring tool and to feed
    *> > the snort intrusion detecti0on system. I have done so for several
    *> > years. After upgrading from the 2.4.20-24.9 to the 2.4.20-27.9
    *> > kernel, my tdpdump no longer functions properly. It is acting like
    *> > perhaps the promiscuous mode is not taking effect, even though an
    *> > ifconfig shows all the monitored interfaces to be in promiscuous
    *> > mode.
    *> >
    *> > Has anybody else seen this? Is there a fix?
    *>
    *> Unfortunately, the 2.4.20-27.9 upgrade, unlike previous rh9 upgrades,
    *> took it upon itself to automatically delete all earlier versions of
    *> the kernel from the system, so I cannot simply edit
    *> /boot/grub/grub.conf to default to the older kernel.
    *>
    *> I think somebody at Red Hat maybe had a little too much holiday happy
    *> juice just before that release was tested... :-<
    *>

    -- 
    Harry Hoffman
    hhoffman@ip-solutions.net
    #----------------------------------------------------------------#
    # Harry: version 4.0a                                            #
    # Known bugs:                                                    #
    # 1) Verbal output may occur before data processing is complete. #
    # 2) Loudspeaker option may activate without being invoked.      #
    # 3) Other bugs as reported                                      #
    #----------------------------------------------------------------#
    -------------------------------------------------
    This mail sent through IpSolutions: http://www.ip-solutions.net/
    -- 
    redhat-list mailing list
    unsubscribe mailto:redhat-list-request@redhat.com?subject=unsubscribe
    https://www.redhat.com/mailman/listinfo/redhat-list
    

  • Next message: Robert Brown: "Re: tcpdump broken after rh9 2.4.20-27.9 kernel upgrade"

    Relevant Pages

    • Re: Network performance degradation from 2.6.11.12 to 2.6.16.20
      ... Harry Edmon wrote: ... The application is the LDM system from UCAR/Unidata. ... the 2.6.16.20 kernel falls way behind with the data ingestion. ... Perhaps a tcpdump of the net traffic will help to determine what's going on. ...
      (Linux-Kernel)
    • Re: Network performance degradation from 2.6.11.12 to 2.6.16.20
      ... Harry Edmon wrote: ... application is the LDM system from UCAR/Unidata ... The 2.6.11.12 kernel does not. ... Perhaps a tcpdump of the net traffic will help to determine what's going on. ...
      (Linux-Kernel)
    • PROBLEM: Strange active ftp failure
      ... On machine 1, active ftp ... As for kernel differences, the machine with no problem is a single-processor ... When I run tcpdump on server it looks like this for an "ls" following login ...
      (Linux-Kernel)
    • Re: System hang when configuring ISA network cards
      ... >> (Linux boot disk) and can get an IP address and ping. ... just the GENERIC kernel from 3.2. ... to get as there aren't any other machines on the switch), I ctrl+c'd tcpdump, ... I did search Google (which presumably includes the mailing list archives) and no ...
      (comp.unix.bsd.openbsd.misc)
    • many packets dropped by kernel
      ... I want to capture some traffic with tcpdump. ... see an greatly number of packets dropped by kernel. ... I flush all ipfw ...
      (freebsd-questions)