Bug ID 989749: Tcpdump command does not show F5 ethtrailer info

Last Modified: Jul 12, 2023

Affected Product(s):
BIG-IP TMOS(all modules)

Known Affected Versions:
13.1.4.1, 13.1.4, 13.1.3.6, 13.1.3.5

Opened: Feb 02, 2021

Severity: 2-Critical

Symptoms

In the packet captures displayed using tcpdump, the packet capture does not display the F5 Ethtrailer information. When the packet capture is read through packet analyzers like Wireshark or TShark, the F5 Ethtrailer information is displayed.

Impact

Difficult to analyze the packet capture in case any issue arises.

Conditions

-- Packet capture is collected with F5 ethernet trailer information ('noise') on an affected software version -- Packet capture is displayed as text output using tcpdump

Workaround

You can use either of the following workarounds: -- Copy the packet capture to a BIG-IP system running an earlier release of BIG-IP software (e.g., TMOS v13.1.3.4). -- Copy the packet capture off of the BIG-IP system and open it in Wireshark or TShark.

Fix Information

None

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips