############################################################################## tcpdump is simular to snoop on Solaris it captures packets from a specific IP location. [root@abby /bin]# tcpdump tcpdump: listening on eth0 14:35:47.250000 0:60:fd:70:e4:70 > 1:80:c2:0:0:0 802.1d ui/C len=43 0000 0000 0080 0000 0081 6531 8800 0000 0a80 0000 60fd 70e4 7080 0100 0114 0002 000f 0000 0050 5555 5555 55 tcpdump: WARNING: compensating for unaligned libpcap packets 14:35:47.320000 172.16.62.222.nterm > aberdeen.netbios-ssn: P 1003735:1003790(55) ack 192799407 win 8760 (DF) 14:35:47.320000 aberdeen.netbios-ssn > 172.16.62.222.nterm: . 1:1461(1460) ack 55 win 7605 (DF) 14:35:47.320000 aberdeen.netbios-ssn > 172.16.62.222.nterm: P 1461:2053(592) ack 55 win 7605 (DF) 14:35:47.320000 172.16.62.222.nterm > aberdeen.netbios-ssn: . ack 2053 win 8760 (DF) 14:35:47.320000 172.16.62.222.1029 > redmond.netbios-ssn: P 2510404:2510459(55) ack 179465478 win 8760 (DF) 14:35:47.320000 redmond.netbios-ssn > 172.16.62.222.1029: . 1:1461(1460) ack 55 win 8375 (DF) 14:35:47.320000 redmond.netbios-ssn > 172.16.62.222.1029: P 1461:2053(592) ack 55 win 8375 (DF) 14:35:47.320000 172.16.62.222.1029 > redmond.netbios-ssn: . ack 20