PACKET DROPPED - 找出丢弃的数据包?

时间:2011-04-07 11:58:02

标签: networking network-programming packet-capture tcpdump

如何通过接口???

打印丢弃的数据包

我有一个丢弃RX数据包的接口,见下文:

eth0      Link encap:Ethernet  HWaddr DE:AD:BE:EF:42:46  
          inet addr:192.168.122.86  Bcast:192.168.122.255  Mask:255.255.255.0
          inet6 addr: fe80::dcad:beff:feef:4246/64 Scope:Link
          UP BROADCAST RUNNING MULTICAST  MTU:1500  Metric:1
          **RX packets:10963521 errors:0 dropped:1006 overruns:0 frame:0**
          TX packets:6221974 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:1000 
          RX bytes:3108701252 (2.8 GiB)  TX bytes:3842229777 (3.5 GiB)
          Interrupt:10 Base address:0xe000 

1 个答案:

答案 0 :(得分:1)

在Windows中,您可以启用丢弃的数据包记录:

步骤1.更改Windows防火墙配置:

auditpol.exe /set /SubCategory:"Filtering Platform Packet Drop" /failure:enable

步骤2.重启防火墙服务

net stop MPSSVC
net start MPSSVC

有关http://technet.microsoft.com/en-us/library/cc754714(v=ws.10).aspx的更多信息。