mirror of
https://github.com/zeek/zeek.git
synced 2025-10-06 00:28:21 +00:00

The first pcap only contained packets from the originator, not the responder. What stands out here is that the Linux kernel doesn't seem to use a symmetric flow hash for the tunneled connection, resulting in a total of four tunnel connections for the two inner connections. Sigh.
2.1 KiB
2.1 KiB