Skip to content

Instantly share code, notes, and snippets.

@seanknox
Created May 11, 2017 23:55
Show Gist options
  • Save seanknox/8dceceb65cf6732232bc81e93c9f44e5 to your computer and use it in GitHub Desktop.
Save seanknox/8dceceb65cf6732232bc81e93c9f44e5 to your computer and use it in GitHub Desktop.
==========================================================
ETH0 / Azure0
==========================================================
root@k8s-agentpool1-37094310-0:~# tcpdump -i eth0 -c 20 -e -p -n host 64.40.107.85
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on eth0, link-type EN10MB (Ethernet), capture size 262144 bytes
23:20:33.403547 00:0d:3a:37:6f:ad > 12:34:56:78:9a:bc, ethertype IPv4 (0x0800), length 74: 10.240.0.4.40292 > 64.40.107.85.80: Flags [S], seq 2639424712, win 29200, options [mss 1460,sackOK,TS val 489756 ecr 0,nop,wscale 7], length 0
23:20:33.425429 12:34:56:78:9a:bc > 00:0d:3a:37:6f:ad, ethertype IPv4 (0x0800), length 74: 64.40.107.85.80 > 10.240.0.4.40292: Flags [S.], seq 3911420238, ack 2639424713, win 14480, options [mss 1460,sackOK,TS val 49502799 ecr 489756,nop,wscale 7], length 0
23:20:33.425443 00:0d:3a:37:6f:ad > 12:34:56:78:9a:bc, ethertype IPv4 (0x0800), length 74: 64.40.107.85.80 > 10.240.0.52.40292: Flags [S.], seq 3911420238, ack 2639424713, win 14480, options [mss 1460,sackOK,TS val 49502799 ecr 489756,nop,wscale 7], length 0
23:20:33.426145 44:4c:a8:06:6e:15 > 00:0d:3a:37:6f:ad, ethertype IPv4 (0x0800), length 74: 64.40.107.85.80 > 10.240.0.52.40292: Flags [S.], seq 3911420238, ack 2639424713, win 14480, options [mss 1418,sackOK,TS val 49502799 ecr 489756,nop,wscale 7], length 0
23:20:33.426188 00:0d:3a:37:6f:ad > 12:34:56:78:9a:bc, ethertype IPv4 (0x0800), length 66: 10.240.0.4.40292 > 64.40.107.85.80: Flags [.], ack 1, win 229, options [nop,nop,TS val 489761 ecr 49502799], length 0
23:20:33.426226 00:0d:3a:37:6f:ad > 12:34:56:78:9a:bc, ethertype IPv4 (0x0800), length 142: 10.240.0.4.40292 > 64.40.107.85.80: Flags [P.], seq 1:77, ack 1, win 229, options [nop,nop,TS val 489761 ecr 49502799], length 76: HTTP: GET / HTTP/1.1
23:20:33.448081 12:34:56:78:9a:bc > 00:0d:3a:37:6f:ad, ethertype IPv4 (0x0800), length 66: 64.40.107.85.80 > 10.240.0.4.40292: Flags [.], ack 77, win 114, options [nop,nop,TS val 49502822 ecr 489761], length 0
23:20:33.448095 00:0d:3a:37:6f:ad > 12:34:56:78:9a:bc, ethertype IPv4 (0x0800), length 66: 64.40.107.85.80 > 10.240.0.52.40292: Flags [.], ack 77, win 114, options [nop,nop,TS val 49502822 ecr 489761], length 0
23:20:33.448264 44:4c:a8:06:6e:15 > 00:0d:3a:37:6f:ad, ethertype IPv4 (0x0800), length 66: 64.40.107.85.80 > 10.240.0.52.40292: Flags [.], ack 77, win 114, options [nop,nop,TS val 49502822 ecr 489761], length 0
23:20:33.448321 00:0d:3a:37:6f:ad > 12:34:56:78:9a:bc, ethertype IPv4 (0x0800), length 54: 10.240.0.52.40292 > 64.40.107.85.80: Flags [R], seq 2639424789, win 0, length 0
23:20:33.473761 12:34:56:78:9a:bc > 00:0d:3a:37:6f:ad, ethertype IPv4 (0x0800), length 683: 64.40.107.85.80 > 10.240.0.4.40292: Flags [P.], seq 1:618, ack 77, win 114, options [nop,nop,TS val 49502849 ecr 489761], length 617: HTTP: HTTP/1.1 302 Moved Temporarily
23:20:33.473789 00:0d:3a:37:6f:ad > 12:34:56:78:9a:bc, ethertype IPv4 (0x0800), length 683: 64.40.107.85.80 > 10.240.0.52.40292: Flags [P.], seq 1:618, ack 77, win 114, options [nop,nop,TS val 49502849 ecr 489761], length 617: HTTP: HTTP/1.1 302 Moved Temporarily
23:20:33.473795 12:34:56:78:9a:bc > 00:0d:3a:37:6f:ad, ethertype IPv4 (0x0800), length 71: 64.40.107.85.80 > 10.240.0.4.40292: Flags [P.], seq 618:623, ack 77, win 114, options [nop,nop,TS val 49502849 ecr 489761], length 5: HTTP
23:20:33.473800 00:0d:3a:37:6f:ad > 12:34:56:78:9a:bc, ethertype IPv4 (0x0800), length 71: 64.40.107.85.80 > 10.240.0.52.40292: Flags [P.], seq 618:623, ack 77, win 114, options [nop,nop,TS val 49502849 ecr 489761], length 5: HTTP
23:20:33.473803 12:34:56:78:9a:bc > 00:0d:3a:37:6f:ad, ethertype IPv4 (0x0800), length 66: 64.40.107.85.80 > 10.240.0.4.40292: Flags [F.], seq 623, ack 77, win 114, options [nop,nop,TS val 49502849 ecr 489761], length 0
23:20:33.473807 00:0d:3a:37:6f:ad > 12:34:56:78:9a:bc, ethertype IPv4 (0x0800), length 66: 64.40.107.85.80 > 10.240.0.52.40292: Flags [F.], seq 623, ack 77, win 114, options [nop,nop,TS val 49502849 ecr 489761], length 0
23:20:33.474087 44:4c:a8:06:6e:15 > 00:0d:3a:37:6f:ad, ethertype IPv4 (0x0800), length 683: 64.40.107.85.80 > 10.240.0.52.40292: Flags [P.], seq 1:618, ack 77, win 114, options [nop,nop,TS val 49502849 ecr 489761], length 617: HTTP: HTTP/1.1 302 Moved Temporarily
23:20:33.474121 44:4c:a8:06:6e:15 > 00:0d:3a:37:6f:ad, ethertype IPv4 (0x0800), length 71: 64.40.107.85.80 > 10.240.0.52.40292: Flags [P.], seq 618:623, ack 77, win 114, options [nop,nop,TS val 49502849 ecr 489761], length 5: HTTP
23:20:33.474140 44:4c:a8:06:6e:15 > 00:0d:3a:37:6f:ad, ethertype IPv4 (0x0800), length 66: 64.40.107.85.80 > 10.240.0.52.40292: Flags [F.], seq 623, ack 77, win 114, options [nop,nop,TS val 49502849 ecr 489761], length 0
23:20:33.474191 00:0d:3a:37:6f:ad > 12:34:56:78:9a:bc, ethertype IPv4 (0x0800), length 54: 10.240.0.52.40292 > 64.40.107.85.80: Flags [R], seq 2639424789, win 0, length 0
==========================================================
Container Iface
==========================================================
root@k8s-agentpool1-37094310-0:~# tcpdump -i veth9aee76c -c 20 -e -p -n host 64.40.107.85
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on veth9aee76c, link-type EN10MB (Ethernet), capture size 262144 bytes
23:20:33.403526 96:7d:17:7e:04:d0 > 12:34:56:78:9a:bc, ethertype IPv4 (0x0800), length 74: 10.240.0.52.40292 > 64.40.107.85.80: Flags [S], seq 2639424712, win 29200, options [mss 1460,sackOK,TS val 489756 ecr 0,nop,wscale 7], length 0
23:20:33.426158 44:4c:a8:06:6e:15 > 96:7d:17:7e:04:d0, ethertype IPv4 (0x0800), length 74: 64.40.107.85.80 > 10.240.0.52.40292: Flags [S.], seq 3911420238, ack 2639424713, win 14480, options [mss 1418,sackOK,TS val 49502799 ecr 489756,nop,wscale 7], length 0
23:20:33.426183 96:7d:17:7e:04:d0 > 12:34:56:78:9a:bc, ethertype IPv4 (0x0800), length 66: 10.240.0.52.40292 > 64.40.107.85.80: Flags [.], ack 1, win 229, options [nop,nop,TS val 489761 ecr 49502799], length 0
23:20:33.426218 96:7d:17:7e:04:d0 > 12:34:56:78:9a:bc, ethertype IPv4 (0x0800), length 142: 10.240.0.52.40292 > 64.40.107.85.80: Flags [P.], seq 1:77, ack 1, win 229, options [nop,nop,TS val 489761 ecr 49502799], length 76: HTTP: GET / HTTP/1.1
23:20:33.448295 44:4c:a8:06:6e:15 > 96:7d:17:7e:04:d0, ethertype IPv4 (0x0800), length 66: 64.40.107.85.1 > 10.240.0.52.40292: Flags [.], ack 2639424789, win 114, options [nop,nop,TS val 49502822 ecr 489761], length 0
23:20:33.448316 96:7d:17:7e:04:d0 > 12:34:56:78:9a:bc, ethertype IPv4 (0x0800), length 54: 10.240.0.52.40292 > 64.40.107.85.1: Flags [R], seq 2639424789, win 0, length 0
23:20:33.474119 44:4c:a8:06:6e:15 > 96:7d:17:7e:04:d0, ethertype IPv4 (0x0800), length 683: 64.40.107.85.1 > 10.240.0.52.40292: Flags [P.], seq 0:617, ack 1, win 114, options [nop,nop,TS val 49502849 ecr 489761], length 617
23:20:33.474140 44:4c:a8:06:6e:15 > 96:7d:17:7e:04:d0, ethertype IPv4 (0x0800), length 71: 64.40.107.85.1 > 10.240.0.52.40292: Flags [P.], seq 617:622, ack 1, win 114, options [nop,nop,TS val 49502849 ecr 489761], length 5
23:20:33.474143 44:4c:a8:06:6e:15 > 96:7d:17:7e:04:d0, ethertype IPv4 (0x0800), length 66: 64.40.107.85.1 > 10.240.0.52.40292: Flags [F.], seq 622, ack 1, win 114, options [nop,nop,TS val 49502849 ecr 489761], length 0
23:20:33.474170 96:7d:17:7e:04:d0 > 12:34:56:78:9a:bc, ethertype IPv4 (0x0800), length 54: 10.240.0.52.40292 > 64.40.107.85.1: Flags [R], seq 2639424789, win 0, length 0
23:20:33.474198 96:7d:17:7e:04:d0 > 12:34:56:78:9a:bc, ethertype IPv4 (0x0800), length 54: 10.240.0.52.40292 > 64.40.107.85.1: Flags [R], seq 2639424789, win 0, length 0
23:20:33.474202 96:7d:17:7e:04:d0 > 12:34:56:78:9a:bc, ethertype IPv4 (0x0800), length 54: 10.240.0.52.40292 > 64.40.107.85.1: Flags [R], seq 2639424789, win 0, length 0
23:20:33.646411 96:7d:17:7e:04:d0 > 12:34:56:78:9a:bc, ethertype IPv4 (0x0800), length 142: 10.240.0.52.40292 > 64.40.107.85.80: Flags [P.], seq 1:77, ack 1, win 229, options [nop,nop,TS val 489817 ecr 49502799], length 76: HTTP: GET / HTTP/1.1
23:20:33.668321 44:4c:a8:06:6e:15 > 96:7d:17:7e:04:d0, ethertype IPv4 (0x0800), length 78: 64.40.107.85.1 > 10.240.0.52.40292: Flags [.], ack 1, win 114, options [nop,nop,TS val 49503051 ecr 489817,nop,nop,sack 1 {4294967221:1}], length 0
23:20:33.668343 96:7d:17:7e:04:d0 > 12:34:56:78:9a:bc, ethertype IPv4 (0x0800), length 54: 10.240.0.52.40292 > 64.40.107.85.1: Flags [R], seq 2639424789, win 0, length 0
23:20:33.689076 44:4c:a8:06:6e:15 > 96:7d:17:7e:04:d0, ethertype IPv4 (0x0800), length 683: 64.40.107.85.1 > 10.240.0.52.40292: Flags [P.], seq 0:617, ack 1, win 114, options [nop,nop,TS val 49503072 ecr 489817], length 617
23:20:33.689100 96:7d:17:7e:04:d0 > 12:34:56:78:9a:bc, ethertype IPv4 (0x0800), length 54: 10.240.0.52.40292 > 64.40.107.85.1: Flags [R], seq 2639424789, win 0, length 0
23:20:33.870433 96:7d:17:7e:04:d0 > 12:34:56:78:9a:bc, ethertype IPv4 (0x0800), length 142: 10.240.0.52.40292 > 64.40.107.85.80: Flags [P.], seq 1:77, ack 1, win 229, options [nop,nop,TS val 489873 ecr 49502799], length 76: HTTP: GET / HTTP/1.1
23:20:33.892235 44:4c:a8:06:6e:15 > 96:7d:17:7e:04:d0, ethertype IPv4 (0x0800), length 78: 64.40.107.85.1 > 10.240.0.52.40292: Flags [.], ack 1, win 114, options [nop,nop,TS val 49503283 ecr 489873,nop,nop,sack 1 {4294967221:1}], length 0
23:20:33.892251 96:7d:17:7e:04:d0 > 12:34:56:78:9a:bc, ethertype IPv4 (0x0800), length 54: 10.240.0.52.40292 > 64.40.107.85.1: Flags [R], seq 2639424789, win 0, length 0
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment