Re: Traceroute Mal-formed packets

From: John McLaren (
Date: Thu Mar 06 2003 - 09:39:27 EST

The capture shown in my article was captured with tcpdump on the linux box
performing the traceroute. I used Etherpeek to open the dump so that it
would be more readable.

The reply packets are definitely port unreachables - type 3, code 3. There
is no question about that. It would seem to follow then, that the router is
opening layer 4.


To unsubscribe from this list: send the line "unsubscribe linux-net" in
the body of a message to
More majordomo info at

This archive was generated by hypermail 2b29 : Fri Mar 07 2003 - 22:00:01 EST