# tcpdump -w

**URL:** https://community.zeek.org/t/tcpdump-w/777
**Category:** Zeek
**Created:** [June 17, 2005, 12:48pm UTC](https://community.zeek.org/t/tcpdump-w/777 "2005-06-17T12:48:46Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![Angelita\_de\_Cassia\_C](https://avatars.discourse-cdn.com/v4/letter/a/85e7bf/32.png) [@Angelita\_de\_Cassia\_C](https://community.zeek.org/u/Angelita_de_Cassia_C)
#### Post date: [June 17, 2005, 12:48pm UTC](https://community.zeek.org/t/tcpdump-w/777/1 "2005-06-17T12:48:46Z")

</div>

Now, I test with ./bro -i eth0, and I think the bro detect the scans that I  
simulated.

One question, I pretend to use two interfaces, one is the host managment,  
I'll use it to simulated some attacks or scans and it has an IP address and  
the other is the interface that will receive the alive traffic, this doesn't  
have an IP address.  
Do I need another interface, like the manual says or it's enogh to test the  
Bro ids ?

Thanks!  
Angelita

---

<div class="post-metadata">

### Author: ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)
#### Post date: [May 6, 2022, 3:37pm UTC](https://community.zeek.org/t/tcpdump-w/777/2 "2022-05-06T15:37:31Z")

</div>


