Vlad1983 писал(а):tcpdump
AnswerCount=0
AuthorityCount=0
AddressRecCount=0
QuestionRecords:
Name=FF.URALMASH.RU NameType=0x00 (Workstation)
QuestionType=0x20
QuestionClass=0x1
11:09:24.502583 IP (tos 0x0, ttl 128, id 51482, offset 0, flags [none], proto: UDP (17), length: 78) uztm03121001.uralmash.ru.netbios-ns > 10.11.200.255.netbios-ns: [udp sum ok]
>>> NBT UDP PACKET(137): QUERY; REQUEST; BROADCAST
TrnID=0x9158
OpCode=0
NmFlags=0x11
Rcode=0
QueryCount=1
AnswerCount=0
AuthorityCount=0
AddressRecCount=0
QuestionRecords:
Name=UULTBTEVSZ NameType=0x00 (Workstation)
QuestionType=0x20
QuestionClass=0x1
11:09:24.502600 IP (tos 0x0, ttl 128, id 51483, offset 0, flags [none], proto: UDP (17), length: 78) uztm03121001.uralmash.ru.netbios-ns > 10.11.200.255.netbios-ns: [udp sum ok]
>>> NBT UDP PACKET(137): QUERY; REQUEST; BROADCAST
TrnID=0x9159
OpCode=0
NmFlags=0x11
Rcode=0
QueryCount=1
AnswerCount=0
AuthorityCount=0
AddressRecCount=0
QuestionRecords:
Name=QNEGPXCCEW NameType=0x00 (Workstation)
QuestionType=0x20
QuestionClass=0x1
11:09:24.521119 arp who-has npi3772ca.uralmash.ru tell uztm03121001.uralmash.ru
11:09:24.760547 IP (tos 0xc0, ttl 1, id 0, offset 0, flags [none], proto: UDP (17), length: 48) 10.11.200.5.hsrp > all-routers.mcast.net.hsrp: [udp sum ok] HSRPv0-hello 20: state=active group=0 addr=10.11.200.1 hellotime=1s holdtime=3s priority=140 auth="cisco^@^@^@"
11:09:24.830508 (NOV-ETHII) IPX 00000000.00:26:73:19:7a:ca.4100 > 00000000.ff:ff:ff:ff:ff:ff.0452: ipx-sap-nearest-req FileServer
11:09:24.868173 IP (tos 0x0, ttl 64, id 55179, offset 0, flags [DF], proto: UDP (17), length: 71) elastix.uralmash.ru.51154 > uztm-dc01.uralmash.ru.domain: [bad udp cksum 6e!] 39917+ PTR? 98.200.11.10.in-addr.arpa. (43)
11:09:24.868993 IP (tos 0x0, ttl 63, id 54391, offset 0, flags [none], proto: UDP (17), length: 219) uztm-dc01.uralmash.ru.domain > elastix.uralmash.ru.51154: 39917 q: PTR? 98.200.11.10.in-addr.arpa. 1/6/0 98.200.11.10.in-addr.arpa.[|domain]
11:09:25.252512 IP (tos 0x0, ttl 128, id 51486, offset 0, flags [none], proto: UDP (17), length: 78) uztm03121001.uralmash.ru.netbios-ns > 10.11.200.255.netbios-ns: [udp sum ok]
>>> NBT UDP PACKET(137): QUERY; REQUEST; BROADCAST
TrnID=0x9158
OpCode=0
NmFlags=0x11
Rcode=0
QueryCount=1
AnswerCount=0
AuthorityCount=0
AddressRecCount=0
QuestionRecords:
Name=UULTBTEVSZ NameType=0x00 (Workstation)
QuestionType=0x20
QuestionClass=0x1
11:09:25.252513 IP (tos 0x0, ttl 128, id 51487, offset 0, flags [none], proto: UDP (17), length: 78) uztm03121001.uralmash.ru.netbios-ns > 10.11.200.255.netbios-ns: [udp sum ok]
>>> NBT UDP PACKET(137): QUERY; REQUEST; BROADCAST
TrnID=0x9159
OpCode=0
NmFlags=0x11
Rcode=0
QueryCount=1
AnswerCount=0
AuthorityCount=0
AddressRecCount=0
QuestionRecords:
Name=QNEGPXCCEW NameType=0x00 (Workstation)
QuestionType=0x20
QuestionClass=0x1
11:09:25.296336 IP (tos 0xc0, ttl 1, id 0, offset 0, flags [none], proto: UDP (17), length: 48) 10.11.200.4.hsrp > all-routers.mcast.net.hsrp: [udp sum ok] HSRPv0-hello 20: state=standby group=0 addr=10.11.200.1 hellotime=1s holdtime=3s priority=30 auth="cisco^@^@^@"
11:09:25.598431 802.1d config 8000.00:02:b9:4c:9e:2d.8018 root 10c8.a8:b1:d4:58:5d:00 pathcost 7 age 2 max 20 hello 2 fdelay 15
11:09:25.752544 IP (tos 0xc0, ttl 1, id 0, offset 0, flags [none], proto: UDP (17), length: 48) 10.11.200.5.hsrp > all-routers.mcast.net.hsrp: [udp sum ok] HSRPv0-hello 20: state=active group=0 addr=10.11.200.1 hellotime=1s holdtime=3s priority=140 auth="cisco^@^@^@"
11:09:25.835940 (NOV-ETHII) IPX 00000000.00:26:73:19:7a:ca.4100 > 00000000.ff:ff:ff:ff:ff:ff.0452: ipx-sap-nearest-req FileServer
11:09:26.104045 IP (tos 0xc0, ttl 1, id 0, offset 0, flags [none], proto: UDP (17), length: 48) 10.11.200.4.hsrp > all-routers.mcast.net.hsrp: [udp sum ok] HSRPv0-hello 20: state=standby group=0 addr=10.11.200.1 hellotime=1s holdtime=3s priority=30 auth="cisco^@^@^@"
11:09:26.138203 IP (tos 0x0, ttl 128, id 21300, offset 0, flags [none], proto: UDP (17), length: 78) fin40908.uralmash.ru.netbios-ns > 10.11.200.255.netbios-ns: [udp sum ok]
>>> NBT UDP PACKET(137): QUERY; REQUEST; BROADCAST
TrnID=0x9A1B
OpCode=0
NmFlags=0x11
Rcode=0
QueryCount=1
AnswerCount=0
AuthorityCount=0
AddressRecCount=0
QuestionRecords:
Name=FF.URALMASH.RU NameType=0x00 (Workstation)
QuestionType=0x20
QuestionClass=0x1
11:09:26.653552 IP6 (hlim 1, next-header: UDP (17), length: 109) fe80::9531:b311:de45:2b14.dhcpv6-client > ff02::1:2.dhcpv6-server: dhcp6 solicit (xid=e8a169 (elapsed time 0) (client ID hwaddr/time type 1 time 414070587 001d9269fe24)[|dhcp6ext])
11:09:26.700678 IP (tos 0xc0, ttl 1, id 0, offset 0, flags [none], proto: UDP (17), length: 48) 10.11.200.5.hsrp > all-routers.mcast.net.hsrp: [udp sum ok] HSRPv0-hello 20: state=active group=0 addr=10.11.200.1 hellotime=1s holdtime=3s priority=140 auth="cisco^@^@^@"
11:09:26.841374 00:26:73:19:7a:ca (oui Unknown) > Broadcast OSI Information, send seq 0, rcv seq 17, Flags [Command, Poll], length 46
11:09:26.902509 IP (tos 0x0, ttl 128, id 21301, offset 0, flags [none], proto: UDP (17), length: 78) fin40908.uralmash.ru.netbios-ns > 10.11.200.255.netbios-ns: [udp sum ok]
>>> NBT UDP PACKET(137): QUERY; REQUEST; BROADCAST
TrnID=0x9A1B
OpCode=0
NmFlags=0x11
Rcode=0
QueryCount=1
AnswerCount=0
AuthorityCount=0
AddressRecCount=0
QuestionRecords:
Name=FF.URALMASH.RU NameType=0x00 (Workstation)
QuestionType=0x20
QuestionClass=0x1
11:09:27.041884 IP6 (hlim 1, next-header: UDP (17), length: 84) fe80::21e:bff:fe15:76cd.dhcpv6-client > ff02::1:2.dhcpv6-server: dhcp6 solicit (xid=3a75ea (elapsed time 0) (client ID hwaddr type 1 001e0b1576cd)[|dhcp6ext])
11:09:27.079900 IP (tos 0xc0, ttl 1, id 0, offset 0, flags [none], proto: UDP (17), length: 48) 10.11.200.4.hsrp > all-routers.mcast.net.hsrp: [udp sum ok] HSRPv0-hello 20: state=standby group=0 addr=10.11.200.1 hellotime=1s holdtime=3s priority=30 auth="cisco^@^@^@"
11:09:27.182558 IP (tos 0x0, ttl 128, id 45392, offset 0, flags [none], proto: UDP (17), length: 78) uztm9735.uralmash.ru.netbios-ns > 10.11.200.255.netbios-ns: [udp sum ok]
>>> NBT UDP PACKET(137): QUERY; REQUEST; BROADCAST
TrnID=0xBB69
OpCode=0
NmFlags=0x11
Rcode=0
QueryCount=1
AnswerCount=0
AuthorityCount=0
AddressRecCount=0
QuestionRecords:
Name=SMS_SLP NameType=0x1A (Unknown)
QuestionType=0x20
QuestionClass=0x1
11:09:27.560450 IP (tos 0xc0, ttl 1, id 0, offset 0, flags [none], proto: UDP (17), length: 48) 10.11.200.5.hsrp > all-routers.mcast.net.hsrp: [udp sum ok] HSRPv0-hello 20: state=active group=0 addr=10.11.200.1 hellotime=1s holdtime=3s priority=140 auth="cisco^@^@^@"
11:09:27.602418 802.1d config 8000.00:02:b9:4c:9e:2d.8018 root 10c8.a8:b1:d4:58:5d:00 pathcost 7 age 2 max 20 hello 2 fdelay 15
11:09:27.640437 IP6 (hlim 1, next-header: UDP (17), length: 109) fe80::9531:b311:de45:2b14.dhcpv6-client > ff02::1:2.dhcpv6-server: dhcp6 solicit (xid=e8a169 (elapsed time 100) (client ID hwaddr/time type 1 time 414070587 001d9269fe24)[|dhcp6ext])
11:09:27.666826 IP (tos 0x0, ttl 128, id 21302, offset 0, flags [none], proto: UDP (17), length: 78) fin40908.uralmash.ru.netbios-ns > 10.11.200.255.netbios-ns: [udp sum ok]
>>> NBT UDP PACKET(137): QUERY; REQUEST; BROADCAST
TrnID=0x9A1B
OpCode=0
NmFlags=0x11
Rcode=0
QueryCount=1
AnswerCount=0
AuthorityCount=0
AddressRecCount=0
QuestionRecords:
Name=FF.URALMASH.RU NameType=0x00 (Workstation)
QuestionType=0x20
QuestionClass=0x1
11:09:27.682570 IP6 (hlim 255, next-header: ICMPv6 (58), length: 32) fe80::7004:a178:9cd1:670f > ff02::1:ff45
[icmp6 sum ok] ICMP6, neighbor solicitation, length 32, who has fe80::9531:b311:de45:2b14
source link-address option (1), length 8 (1): bc:ae:c5:bb:fa:08
0x0000: bcae c5bb fa08
11:09:27.682960 IP6 (hlim 255, next-header: ICMPv6 (58), length: 32) fe80::9531:b311:de45:2b14 > ff02::1:ffd1:670f: [icmp6 sum ok] ICMP6, neighbor solicitation, length 32, who has fe80::7004:a178:9cd1:670f
source link-address option (1), length 8 (1): 00:1d:92:69:fe:24
0x0000: 001d 9269 fe24
11:09:27.846801 IPX 00000000.00:26:73:19:7a:ca.4100 > 00000000.ff:ff:ff:ff:ff:ff.0452: ipx-sap-nearest-req FileServer
11:09:27.932483 IP (tos 0x0, ttl 128, id 45394, offset 0, flags [none], proto: UDP (17), length: 78) uztm9735.uralmash.ru.netbios-ns > 10.11.200.255.netbios-ns: [udp sum ok]
>>> NBT UDP PACKET(137): QUERY; REQUEST; BROADCAST
TrnID=0xBB69
OpCode=0
NmFlags=0x11
Rcode=0
QueryCount=1
AnswerCount=0
AuthorityCount=0
AddressRecCount=0
QuestionRecords:
Name=SMS_SLP NameType=0x1A (Unknown)
QuestionType=0x20
QuestionClass=0x1
11:09:28.023848 IP (tos 0xc0, ttl 1, id 0, offset 0, flags [none], proto: UDP (17), length: 48) 10.11.200.4.hsrp > all-routers.mcast.net.hsrp: [udp sum ok] HSRPv0-hello 20: state=standby group=0 addr=10.11.200.1 hellotime=1s holdtime=3s priority=30 auth="cisco^@^@^@"
11:09:28.389030 IP (tos 0x0, ttl 63, id 42531, offset 0, flags [none], proto: UDP (17), length: 615) 195.58.3.150.5080 > elastix.uralmash.ru.sip: SIP, length: 587
OPTIONS sip:10.11.200.20;transport=udp SIP/2.0
Via: S\377\3771\000\000\000\220\210\226\011\000\000\000\000\000\000\000\000\001\000\000\000\001\000\000\000\001\000\000\000\000\000\000\000\000\000\000\000nisplus\000\000\000\000\0001\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\001\000\000\000\001\000\000\000\000\000\000\000\000\000\000\000files\000\000\000\000\000\000\000\031\000\000\000\010\211\226\011\330\210\226\011ethers\000\000\000\000\000\0001\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\001\000\000\000\001\000\000\000\270\200\226\011\220\200\226\011files\000\000\000\000\000\000\000\031\000\000\000P\211\226\011 \211\226\011netmasks\000\000\000\0001\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\001\000\000\000\001\000\000\000\000\000\000\000\000\000\000\000files\000\000\000\000\000\000\000\031\000\000\000\230\211\226\011h\211\226\011networks\000\000\000\0001\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\001\000\000\000\001\000\000\000\000\000\000\000\000\000\000\000files\000\000\000\000\000\000\000\031\000\000\000(\205\226\011\260\211\226\011protocols\000\000\0001\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\001\000\000\000\001\000\000\000\000\000\000\000\000\000\000\000files\000\000\000\000\000\000\0001\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\001\000\000\000\001\000\000\000\000\000\000\000\000\000\000\000files\000\000\000\000\000\000\000\031\000\000\000X\212\226\011(\212\226\011services\000\000\000\0001\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\001\000\000\000\001\000\000\000\270\200\226\011\010\204\226\011files\000\000\000\000\000\000\000\031\000\000\000\240\212\226\011p\212\226\011netgroup\000\000\000\0001\000\000
0x0000: 4f50 5449 4f4e 5320 7369 703a 3130 2e31
0x0010: 312e 3230 302e 3230 3b74 7261 6e73 706f
0x0020: 7274 3d75 6470 2053 4950 2f32 2e30 0d0a
0x0030: 5669 613a 2053
11:09:28.389209 IP (tos 0x60, ttl 64, id 47414, offset 0, flags [none], proto: UDP (17), length: 516) elastix.uralmash.ru.sip > 195.58.3.150.5080: SIP, length: 488
SIP/2.0 200 OK
Via: SIP/2.0/UDP 195.58.3.150:5080;bra\377\3771\000\000\000\220\210\226\011\000\000\000\000\000\000\000\000\001\000\000\000\001\000\000\000\001\000\000\000\000\000\000\000\000\000\000\000nisplus\000\000\000\000\0001\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\001\000\000\000\001\000\000\000\000\000\000\000\000\000\000\000files\000\000\000\000\000\000\000\031\000\000\000\010\211\226\011\330\210\226\011ethers\000\000\000\000\000\0001\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\001\000\000\000\001\000\000\000\270\200\226\011\220\200\226\011files\000\000\000\000\000\000\000\031\000\000\000P\211\226\011 \211\226\011netmasks\000\000\000\0001\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\001\000\000\000\001\000\000\000\000\000\000\000\000\000\000\000files\000\000\000\000\000\000\000\031\000\000\000\230\211\226\011h\211\226\011networks\000\000\000\0001\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\001\000\000\000\001\000\000\000\000\000\000\000\000\000\000\000files\000\000\000\000\000\000\000\031\000\000\000(\205\226\011\260\211\226\011protocols\000\000\0001\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\001\000\000\000\001\000\000\000\000\000\000\000\000\000\000\000files\000\000\000\000\000\000\0001\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\001\000\000\000\001\000\000\000\000\000\000\000\000\000\000\000files\000\000\000\000\000\000\000
0x0000: 5349 502f 322e 3020 3230 3020 4f4b 0d0a
0x0010: 5669 613a 2053 4950 2f32 2e30 2f55 4450
0x0020: 2031 3935 2e35 382e 332e 3135 303a 3530
0x0030: 3830 3b62 7261
11:09:28.520335 IP (tos 0xc0, ttl 1, id 0, offset 0, flags [none], proto: UDP (17), length: 48) 10.11.200.5.hsrp > all-routers.mcast.net.hsrp: [udp sum ok] HSRPv0-hello 20: state=active group=0 addr=10.11.200.1 hellotime=1s holdtime=3s priority=140 auth="cisco^@^@^@"
11:09:28.682456 IP (tos 0x0, ttl 128, id 45395, offset 0, flags [none], proto: UDP (17), length: 78) uztm9735.uralmash.ru.netbios-ns > 10.11.200.255.netbios-ns: [udp sum ok]
>>> NBT UDP PACKET(137): QUERY; REQUEST; BROADCAST
TrnID=0xBB69
OpCode=0
NmFlags=0x11
Rcode=0
QueryCount=1
AnswerCount=0
AuthorityCount=0
AddressRecCount=0
QuestionRecords:
Name=SMS_SLP NameType=0x1A (Unknown)
QuestionType=0x20
QuestionClass=0x1
11:09:28.852167 (NOV-ETHII) IPX 00000000.00:26:73:19:7a:ca.4100 > 00000000.ff:ff:ff:ff:ff:ff.0452: ipx-sap-nearest-req FileServer
11:09:28.856062 IP (tos 0xc0, ttl 1, id 0, offset 0, flags [none], proto: UDP (17), length: 48) 10.11.200.4.hsrp > all-routers.mcast.net.hsrp: [udp sum ok] HSRPv0-hello 20: state=standby group=0 addr=10.11.200.1 hellotime=1s holdtime=3s priority=30 auth="cisco^@^@^@"
11:09:29.512247 IP (tos 0xc0, ttl 1, id 0, offset 0, flags [none], proto: UDP (17), length: 48) 10.11.200.5.hsrp > all-routers.mcast.net.hsrp: [udp sum ok] HSRPv0-hello 20: state=active group=0 addr=10.11.200.1 hellotime=1s holdtime=3s priority=140 auth="cisco^@^@^@"
11:09:29.615803 802.1d config 8000.00:02:b9:4c:9e:2d.8018 root 10c8.a8:b1:d4:58:5d:00 pathcost 7 age 2 max 20 hello 2 fdelay 15
11:09:29.640319 IP6 (hlim 1, next-header: UDP (17), length: 109) fe80::9531:b311:de45:2b14.dhcpv6-client > ff02::1:2.dhcpv6-server: dhcp6 solicit (xid=e8a169 (elapsed time 300) (client ID hwaddr/time type 1 time 414070587 001d9269fe24)[|dhcp6ext])
11:09:29.751683 IP (tos 0xc0, ttl 1, id 0, offset 0, flags [none], proto: UDP (17), length: 48) 10.11.200.4.hsrp > all-routers.mcast.net.hsrp: [udp sum ok] HSRPv0-hello 20: state=standby group=0 addr=10.11.200.1 hellotime=1s holdtime=3s priority=30 auth="cisco^@^@^@"
11:09:29.857688 (NOV-ETHII) IPX 00000000.00:26:73:19:7a:ca.4100 > 00000000.ff:ff:ff:ff:ff:ff.0452: ipx-sap-nearest-req FileServer
11:09:29.869690 IP (tos 0x0, ttl 64, id 60181, offset 0, flags [DF], proto: UDP (17), length: 71) elastix.uralmash.ru.51818 > uztm-dc01.uralmash.ru.domain: [bad udp cksum 2e05!] 302+ PTR? 39.200.11.10.in-addr.arpa. (43)
11:09:29.870529 IP (tos 0x0, ttl 63, id 54392, offset 0, flags [none], proto: UDP (17), length: 128) uztm-dc01.uralmash.ru.domain > elastix.uralmash.ru.51818: 302 NXDomain q: PTR? 39.200.11.10.in-addr.arpa. 0/1/0 ns: 11.10.in-addr.arpa. (100)
[3]+ Stopped tcpdump -vvv
[root@elastix ~]#