1822457 Members
2548 Online
109642 Solutions
New Discussion юеВ

Re: TCP Port monitoring

 
Mike Hutchins_2
New Member

TCP Port monitoring

I need to find out if there is a way to monitor data coming in to a particular
TCP port. I have a CAD application running a phantom process on port 142 and I
need to see if a different server is sending data to that port. Thanks!
3 REPLIES 3
Sajith Mannadiar
Occasional Advisor

Re: TCP Port monitoring

Hi,

You can use the tool 'tcpdump' for this.

If you are running hp-ux, you can download this tool from
http://hpux.csc.liv.ac.uk

Regards
Sajith
Mike Hutchins_2
New Member

Re: TCP Port monitoring

Thanks!

Re: TCP Port monitoring

tcpdump has some disadvantages on HP-UX.
Use the built in nettl and netfmt like in my scripts "traceon" and "traceoff"
below. To trace port 141 you say:

./traceon 141 | less
and if you're finished use
./traceoff

--- file traceon ---
#! /bin/ksh -p
echo Tracing TCP and UPD port $1 in

echo filter tcp_dport $1 > /root/scripts/netfmt.filter
echo filter udp_dport $1 >> /root/scripts/netfmt.filter

nettl -traceoff -entity all > /dev/null 2> /dev/null
# Turn off all tracing
nettl -traceon pduin -entity all -size 128 -file /tmp/raw
# Turn on tracing for data in (pduin)
netfmt -N -F -l -f /tmp/raw.TRC0 -c /root/scripts/netfmt.filter
# display that
--- end file traceon ---

---file traceoff ---
#! /bin/ksh -p
echo Tracing of TCP and UPD off!
nettl -traceoff -entity all > /dev/null 2> /dev/null
# Turn off all tracing
--- end file traceoff ---