How does TCP dump work?
-
Recently I have started to venture into the noble field of packet sniffing ::). I have been wondering about the following: At what point does TCPdump capture packets? Before or after any firewalling? In other words, will tcpdump see traffic to the machine its being run from even if this traffic is rejected by the firewall?