TCP 3次握手 MAC分析
tcpdump -i eth0 -nn -X -e port 9010
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on eth0, link-type EN10MB (Ethernet), capture size 262144 bytes
03:16:21.727402 7e:e8:8c:a6:3e:22 > 00:00:5e:00:01:6e, ethertype IPv4 (0x0800), length 66: 167.71.156.49.29775 > 157.245.121.35.9010: Flags [S], seq 763495115, win 29200, options [mss 1460,nop,nop,sackOK,nop,wscale 8], length 0
....
03:16:21.805106 9c:cc:83:8d:78:74 > 7e:e8:8c:a6:3e:22, ethertype IPv4 (0x0800), length 66: 157.245.121.35.9010 > 167.71.156.49.29775: Flags [S.], seq 636224093, ack 763495116, win 29200, options [mss 1460,nop,nop,sackOK,nop,wscale 8], length 0
....
03:16:21.805179 7e:e8:8c:a6:3e:22 > 00:00:5e:00:01:6e, ethertype IPv4 (0x0800), length 54: 167.71.156.49.29775 > 157.245.121.35.9010: Flags [.], ack 1, win 115, length 0
7e:e8:8c:a6:3e:22 本机167.71.156.49 对应MAC
00:00:5e:00:01:6e 本机网关MAC
两台云主机都有公网IP,tcpdump抓包,发现3次握手上面的MAC地址不一样,谁能给解释下?为啥SYN ACK不经过网关MAC