IDP Support Notes

4.Start ethereal packet capturing.

5.Initiate eMule connection from the internal PC, be sure to reduce unnecessary traffic if possible.

6.Stop packet capturing.

7.Analyze the packet. In ethereal, you will get 3 sub-windows. The first window displays summary of each packet in time sequence. In the second window, you can check the parsed details of the selected packet. In the third window, the selected packet is displayed in Hexadecimal and ASCII format respectively. The basic level to analyze a connection’s pattern is to trace the ASCII format of the packet. After observing, we can see eMule client sends “eDonkey TCP: Hello” after TCP three way handshaking. And each time, you can see the key word of http://emule-project.net appears in TCP payload.

19

All contents copyright (c) 2004 ZyXEL Communications Corporation.