Understanding Networks — Professor Tom Igoe

The Packet Sniffer Times

Here is whats up on my computer on a regular Tuesday morning.

Loopback: lo0

Every 4 second it goes again out of ICMPv6, the source and the destination are the same every time. Its very consistent. The length is 136 every time, Destination Unreachable (Address Reachable). I think its just sending to itself.

Wireshark activity sparkline for lo0 showing a steady, evenly spaced pulse

Pretty much like this forever.

When I unplug my phone however,

Wireshark activity sparkline for lo0 after unplugging the phone, with only two spikes

Now I am sniffing on this line, I plugged my phone back in and it stopped

Lets see what happens when I try my airpods, still nothing

I just launched my webpage and a shit ton of packets came at once, about 100
all 127.0.0.1
Now mdns is talking

en0:

This is like packet city,
I see TCP, QUIC, 0X6970 from my Sonos_xx:xx:xx, TLSv1.2 UDP ARP, DNS, MDNS.

All flying by like crazy animals

QUIC
general purpose transport network protocol designed by Jim Roskind at google. From 2012 to announced in 2013. Chrome uses it the most. Improves on TCP with multiplexing. Supposed to obsolete TCP (not working)

is really interesting, sorting by

quic

I get a lot of messages lasting less than a second back and forth between my IP and a destination IP.
That IP is 17.248.199.12

It looks like its not google using this one today, its apple. I checked who is and ran a very long trace route.

The pattern they establish is initial, Handshake, protected payload, and repeat.

The packet is super long.

claude says its icloud syncing in the background.

I learned this about TLSv1.2

TLSv1.2
For secure communications. Used for HTTPS.

Widely used in email, instant messaging, voice over IP

and ARP

ARP
Address Resolution Protocol

for discovering the link layer address, such as mac address.

and DNS

DNS
Domain Name System
name service for IP addresses

and MDNS

MDNS
Multicast DNS

resolves hostnames to IP addresses within small networks that do not include a local name server.

whatever that means.

This feels to me like sampling a pond for life.

Toms Questions:

All this traffic I am measuring now is from ethernet.

Statistic- protocol hierarchy
There is no plain http, but HTTPS is 52% of my bytes

Lowest Percent, less than 1:
ARP
ICMP
UDP

Im going over to my EC2 Instance
and running

sudo tcpdump -i enX0

the basic format of this command is

tcpdump [options] [expression]

Im going to need to book office hours to get help here.