[Snort-users] capturing arp
radamson at ...2127...
Mon Apr 14 06:31:12 EDT 2003
That's not true; been using NAI Sniffer, Ethereal, etc, to view arp
requests and responses for years. There could be some specific nic
and OS that does not allow capturing, but haven't seen one in 20+
years of doing detailed protocol analysis. The TCP/IP protocol stack
(including the ARP functions) have always been implemented in software
> In all of my tests you can't capture arp packets because they are
> handled in hardware. If you use Nemesis and generate an ARP packet it
> isn't captured by Ethereal or Network General Sniffer.
More information about the Snort-users