> You could try -X, but I usually use -s 9999 -w /tmp/file.dump and
> examine the dump file in wireshark locally.
That did it, I'm able to see the data now.
12:43:34.322207 IP 192.168.1.200.hotu-chat > www.xxx.com.http: P 1:488(487) ack
1 win 65535
0x0000: 4500 020f 55c1 4000 8006 1eb2 c0a8 01c8 E...U.@.........
0x0010: c0a8 015d 0d79 0050 0d59 51eb 3fcf d93c ...].y.P.YQ.?..<
0x0020: 5018 ffff d9cd 0000 4745 5420 2f20 4854 P.......GET./.HT
0x0030: 5450 2f31 2e31 0d0a 486f 7374 3a20 3139 TP/1.1..Host:.19
0x0040: 322e 3136 382e 312e 3933 0d0a 5573 6572 2.168.1.93..User
0x0050: 2d41 -A
12:43:34.322299 IP www.xxx.com.http > 192.168.1.200.hotu-chat: . ack 488 win
6432
0x0000: 4500 0028 6270 4000 4006 53ea c0a8 015d E..(bp@.@.S....]
0x0010: c0a8 01c8 0050 0d79 3fcf d93c 0d59 53d2 .....P.y?..<.YS.
0x0020: 5010 1920 8a3e 0000 P....>..
12:43:34.387595 IP www.xxx.com.http > 192.168.1.200.hotu-chat: . 1:1461(1460)
ack 488 win 6432
0x0000: 4500 05dc 6271 4000 4006 4e35 c0a8 015d E...bq@.@.N5...]
0x0010: c0a8 01c8 0050 0d79 3fcf d93c 0d59 53d2 .....P.y?..<.YS.
0x0020: 5010 1920 b66a 0000 4854 5450 2f31 2e31 P....j..HTTP/1.1
0x0030: 2032 3030 204f 4b0d 0a44 6174 653a 2057 .200.OK..Date:.W
0x0040: 6564 2c20 3135 2041 7072 2032 3030 3920 ed,.15.Apr.2009.
0x0050: 3137 17
So, the relevant parts I'm looking for are the GET HTTP and reply right?
_______________________________________________
Please read the documentation before posting - it's available at:
http://www.linuxvirtualserver.org/
LinuxVirtualServer.org mailing list - lvs-users@xxxxxxxxxxxxxxxxxxxxxx
Send requests to lvs-users-request@xxxxxxxxxxxxxxxxxxxxxx
or go to http://lists.graemef.net/mailman/listinfo/lvs-users
|