Jamie Wilkinson wrote:

This one time, at band camp, Wim Kerkhoff wrote:
I've got 'vlan and ...' in my pcap_filter variable, and that works.


ith e1000? What kernel?

A pair of e100s actually, but I'm surprised that you think the driver is the
problem.

I only mention the vlan flag because I also count on a 802.1Q tagged network
and was counting no packets until I added 'vlan' to the expression.

Trust me :-)

I was very surprised too. The exact same vlan filter string for tcpdump that works with e100 and tg3 does not work with e1000. You can sniff individual vlans ok, but not the trunk port. The most you'll see is traffic originating from the the host to the layer 2 switch. The tags on inbound ethernet frames from the Layer 2 are all optimized away by the e1000 drivers.

Wim

Reply via email to