Hi,
I didn't see that the other format doesnt contain the mac address. As you said I have to do another capture.
As we can see here the ethernet interface is 10.20.100.43/24 - e4:5f:01:70:e8:5c
And I connected the wifi interface for testing and management purpose 192.168.2.219/24 - e4:5f:01:70:e8:5d
@gp0043:~$ ip a
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
inet 127.0.0.1/8 scope host lo
valid_lft forever preferred_lft forever
inet6 ::1/128 scope host
valid_lft forever preferred_lft forever
2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc mq state UP group default qlen 1000
link/ether e4:5f:01:70:e8:5c brd ff:ff:ff:ff:ff:ff
inet 10.20.100.43/24 metric 100 brd 10.20.100.255 scope global dynamic eth0
valid_lft 53471sec preferred_lft 53471sec
inet6 fe80::e65f:1ff:fe70:e85c/64 scope link
valid_lft forever preferred_lft forever
3: wlan0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc fq_codel state UP group default qlen 1000
link/ether e4:5f:01:70:e8:5d brd ff:ff:ff:ff:ff:ff
inet 192.168.2.219/24 metric 1 brd 192.168.2.255 scope global dynamic wlan0
valid_lft 226267sec preferred_lft 226267sec
inet6 fe80::e65f:1ff:fe70:e85d/64 scope link
valid_lft forever preferred_lft forever
Here's a new capture with every details
--- Start Of Stream ---
tcpdump: listening on all_lan_sniff, link-type EN10MB (Ethernet), snapshot length 262144 bytes
22:27:55.495799 cc:03:d9:ca:a3:ee > e4:5f:01:70:e8:5c, ethertype 802.1Q (0x8100), length 70: vlan 100, p 0, ethertype IPv4 (0x0800), (tos 0x0, ttl 120, id 20234, offset 0, flags [DF], proto TCP (6), length 52)
184.145.157.57.49381 > 10.20.100.43.50022: Flags [S], cksum 0xd55b (correct), seq 3564143126, win 64240, options [mss 1434,nop,wscale 8,nop,nop,sackOK], length 0
0x0000: 4500 0034 4f0a 4000 7806 efaf b891 9d39 E..4O.@.x......9
0x0010: 0a14 642b c0e5 c366 d470 8216 0000 0000 ..d+...f.p......
0x0020: 8002 faf0 d55b 0000 0204 059a 0103 0308 .....[..........
0x0030: 0101 0402 ....
22:27:56.497612 cc:03:d9:ca:a3:ee > e4:5f:01:70:e8:5c, ethertype 802.1Q (0x8100), length 70: vlan 100, p 0, ethertype IPv4 (0x0800), (tos 0x0, ttl 120, id 20235, offset 0, flags [DF], proto TCP (6), length 52)
184.145.157.57.49381 > 10.20.100.43.50022: Flags [S], cksum 0xd549 (correct), seq 3564143126, win 64240, options [mss 1452,nop,wscale 8,nop,nop,sackOK], length 0
0x0000: 4500 0034 4f0b 4000 7806 efae b891 9d39 E..4O.@.x......9
0x0010: 0a14 642b c0e5 c366 d470 8216 0000 0000 ..d+...f.p......
0x0020: 8002 faf0 d549 0000 0204 05ac 0103 0308 .....I..........
0x0030: 0101 0402 ....
22:27:58.505212 cc:03:d9:ca:a3:ee > e4:5f:01:70:e8:5c, ethertype 802.1Q (0x8100), length 70: vlan 100, p 0, ethertype IPv4 (0x0800), (tos 0x0, ttl 120, id 20236, offset 0, flags [DF], proto TCP (6), length 52)
184.145.157.57.49381 > 10.20.100.43.50022: Flags [S], cksum 0xd549 (correct), seq 3564143126, win 64240, options [mss 1452,nop,wscale 8,nop,nop,sackOK], length 0
0x0000: 4500 0034 4f0c 4000 7806 efad b891 9d39 E..4O.@.x......9
0x0010: 0a14 642b c0e5 c366 d470 8216 0000 0000 ..d+...f.p......
0x0020: 8002 faf0 d549 0000 0204 05ac 0103 0308 .....I..........
0x0030: 0101 0402 ....
22:28:02.520922 cc:03:d9:ca:a3:ee > e4:5f:01:70:e8:5c, ethertype 802.1Q (0x8100), length 70: vlan 100, p 0, ethertype IPv4 (0x0800), (tos 0x0, ttl 120, id 20237, offset 0, flags [DF], proto TCP (6), length 52)
184.145.157.57.49381 > 10.20.100.43.50022: Flags [S], cksum 0xd549 (correct), seq 3564143126, win 64240, options [mss 1452,nop,wscale 8,nop,nop,sackOK], length 0
0x0000: 4500 0034 4f0d 4000 7806 efac b891 9d39 E..4O.@.x......9
0x0010: 0a14 642b c0e5 c366 d470 8216 0000 0000 ..d+...f.p......
0x0020: 8002 faf0 d549 0000 0204 05ac 0103 0308 .....I..........
0x0030: 0101 0402 ....
22:28:08.021914 e4:5f:01:70:e7:e4 > cc:03:d9:ca:a3:ee, ethertype 802.1Q (0x8100), length 106: vlan 100, p 0, ethertype IPv4 (0x0800), (tos 0x10, ttl 64, id 63114, offset 0, flags [DF], proto TCP (6), length 88)
10.20.100.42.60028 > 52.149.141.62.50022: Flags [P.], cksum 0x96c1 (correct), seq 2536491953:2536491989, ack 4271154822, win 501, options [nop,nop,TS val 617840332 ecr 3856881348], length 36
0x0000: 4510 0058 f68a 4000 4006 13f4 0a14 642a E..X..@.@.....d*
0x0010: 3495 8d3e ea7c c366 972f cbb1 fe94 a686 4..>.|.f./......
0x0020: 8018 01f5 96c1 0000 0101 080a 24d3 7ecc ............$.~.
0x0030: e5e3 56c4 6a3c 8d9b e855 d841 6fba 4dc9 ..V.j<...U.Ao.M.
0x0040: c52f 83ca 31fa b81a b3a6 0aab 0b6d d135 ./..1........m.5
0x0050: 5594 c731 d674 e06e U..1.t.n
22:28:08.048925 cc:03:d9:ca:a3:ee > e4:5f:01:70:e7:e4, ethertype 802.1Q (0x8100), length 106: vlan 100, p 0, ethertype IPv4 (0x0800), (tos 0x10, ttl 44, id 33248, offset 0, flags [DF], proto TCP (6), length 88)
52.149.141.62.50022 > 10.20.100.42.60028: Flags [P.], cksum 0x0756 (correct), seq 1:37, ack 36, win 501, options [nop,nop,TS val 3856941426 ecr 617840332], length 36
0x0000: 4510 0058 81e0 4000 2c06 9c9e 3495 8d3e E..X..@.,...4..>
0x0010: 0a14 642a c366 ea7c fe94 a686 972f cbd5 ..d*.f.|...../..
0x0020: 8018 01f5 0756 0000 0101 080a e5e4 4172 .....V........Ar
0x0030: 24d3 7ecc cd2d b222 dbb4 1e48 8f12 865c $.~..-."...H...\
0x0040: 01f8 f79b e741 e6d9 8d00 476a ae5d 277c .....A....Gj.]'|
0x0050: 4ec6 2061 45b1 06b0 N..aE...
22:28:08.049125 e4:5f:01:70:e7:e4 > cc:03:d9:ca:a3:ee, ethertype 802.1Q (0x8100), length 70: vlan 100, p 0, ethertype IPv4 (0x0800), (tos 0x10, ttl 64, id 63115, offset 0, flags [DF], proto TCP (6), length 52)
10.20.100.42.60028 > 52.149.141.62.50022: Flags [.], cksum 0xc37b (correct), seq 36, ack 37, win 501, options [nop,nop,TS val 617840360 ecr 3856941426], length 0
0x0000: 4510 0034 f68b 4000 4006 1417 0a14 642a E..4..@.@.....d*
0x0010: 3495 8d3e ea7c c366 972f cbd5 fe94 a6aa 4..>.|.f./......
0x0020: 8010 01f5 c37b 0000 0101 080a 24d3 7ee8 .....{......$.~.
0x0030: e5e4 4172 ..Ar
22:28:08.426935 e4:5f:01:70:e8:f5 > cc:03:d9:ca:a3:ee, ethertype 802.1Q (0x8100), length 106: vlan 100, p 0, ethertype IPv4 (0x0800), (tos 0x10, ttl 64, id 2816, offset 0, flags [DF], proto TCP (6), length 88)
10.20.100.41.58794 > 52.149.141.62.50022: Flags [P.], cksum 0x834a (correct), seq 2125455321:2125455357, ack 731346957, win 501, options [nop,nop,TS val 1745384137 ecr 3856881789], length 36
0x0000: 4510 0058 0b00 4000 4006 ff7f 0a14 6429 E..X..@.@.....d)
0x0010: 3495 8d3e e5aa c366 7eaf dfd9 2b97 780d 4..>...f~...+.x.
0x0020: 8018 01f5 834a 0000 0101 080a 6808 72c9 .....J......h.r.
0x0030: e5e3 587d 6e3a 0b7f 33b6 fe6b 36ac c7af ..X}n:..3..k6...
0x0040: bc1a 4bf1 8e3d d3df 3266 04b4 f7f5 6f75 ..K..=..2f....ou
0x0050: 223b f978 4abf e374 ";.xJ..t
22:28:08.453202 cc:03:d9:ca:a3:ee > e4:5f:01:70:e8:f5, ethertype 802.1Q (0x8100), length 106: vlan 100, p 0, ethertype IPv4 (0x0800), (tos 0x10, ttl 44, id 22751, offset 0, flags [DF], proto TCP (6), length 88)
52.149.141.62.50022 > 10.20.100.41.58794: Flags [P.], cksum 0x5dc4 (correct), seq 1:37, ack 36, win 501, options [nop,nop,TS val 3856941831 ecr 1745384137], length 36
0x0000: 4510 0058 58df 4000 2c06 c5a0 3495 8d3e E..XX.@.,...4..>
0x0010: 0a14 6429 c366 e5aa 2b97 780d 7eaf dffd ..d).f..+.x.~...
0x0020: 8018 01f5 5dc4 0000 0101 080a e5e4 4307 ....].........C.
0x0030: 6808 72c9 4aba e83b fd46 5d90 dfa8 de02 h.r.J..;.F].....
0x0040: e593 3c1a 92fa 4860 a515 a744 9e68 cba2 ..<...H`...D.h..
0x0050: 2d60 fa36 7be4 9542 -`.6{..B
22:28:08.453397 e4:5f:01:70:e8:f5 > cc:03:d9:ca:a3:ee, ethertype 802.1Q (0x8100), length 70: vlan 100, p 0, ethertype IPv4 (0x0800), (tos 0x10, ttl 64, id 2817, offset 0, flags [DF], proto TCP (6), length 52)
10.20.100.41.58794 > 52.149.141.62.50022: Flags [.], cksum 0x9558 (correct), seq 36, ack 37, win 501, options [nop,nop,TS val 1745384163 ecr 3856941831], length 0
0x0000: 4510 0034 0b01 4000 4006 ffa2 0a14 6429 E..4..@.@.....d)
0x0010: 3495 8d3e e5aa c366 7eaf dffd 2b97 7831 4..>...f~...+.x1
0x0020: 8010 01f5 9558 0000 0101 080a 6808 72e3 .....X......h.r.
0x0030: e5e4 4307 ..C.
22:28:08.921665 e4:5f:01:70:e9:3d > cc:03:d9:ca:a3:ee, ethertype 802.1Q (0x8100), length 106: vlan 100, p 0, ethertype IPv4 (0x0800), (tos 0x10, ttl 64, id 22082, offset 0, flags [DF], proto TCP (6), length 88)
10.20.100.44.57012 > 52.149.141.62.50022: Flags [P.], cksum 0x94f9 (correct), seq 4136253688:4136253724, ack 1811290382, win 501, options [nop,nop,TS val 2225748732 ecr 3856882256], length 36
0x0000: 4510 0058 5642 4000 4006 b43a 0a14 642c E..XVB@.@..:..d,
0x0010: 3495 8d3e deb4 c366 f68a 38f8 6bf6 190e 4..>...f..8.k...
0x0020: 8018 01f5 94f9 0000 0101 080a 84aa 3afc ..............:.
0x0030: e5e3 5a50 470d 66e2 426a b040 5611 ca8a ..ZPG.f.Bj.@V...
0x0040: b9b9 ea8e 6d76 b3ad f6e4 debf 0ebe ac73 ....mv.........s
0x0050: b023 bebd 3b74 9741 .#..;t.A
22:28:08.948148 cc:03:d9:ca:a3:ee > e4:5f:01:70:e9:3d, ethertype 802.1Q (0x8100), length 98: vlan 100, p 0, ethertype IPv4 (0x0800), (tos 0x10, ttl 45, id 402, offset 0, flags [DF], proto TCP (6), length 80)
52.149.141.62.50022 > 10.20.100.44.57012: Flags [P.], cksum 0x256e (correct), seq 1:29, ack 36, win 501, options [nop,nop,TS val 3856942326 ecr 2225748732], length 28
0x0000: 4510 0050 0192 4000 2d06 1bf3 3495 8d3e E..P..@.-...4..>
0x0010: 0a14 642c c366 deb4 6bf6 190e f68a 391c ..d,.f..k.....9.
0x0020: 8018 01f5 256e 0000 0101 080a e5e4 44f6 ....%n........D.
0x0030: 84aa 3afc 4b7a 4dd1 fa72 7b34 f324 2e1b ..:.KzM..r{4.$..
0x0040: f252 9340 3bbc 2bce c03b f3eb 93c0 78a0 .R.@;.+..;....x.
22:28:08.948395 e4:5f:01:70:e9:3d > cc:03:d9:ca:a3:ee, ethertype 802.1Q (0x8100), length 70: vlan 100, p 0, ethertype IPv4 (0x0800), (tos 0x10, ttl 64, id 22083, offset 0, flags [DF], proto TCP (6), length 52)
10.20.100.44.57012 > 52.149.141.62.50022: Flags [.], cksum 0x0335 (correct), seq 36, ack 29, win 501, options [nop,nop,TS val 2225748759 ecr 3856942326], length 0
0x0000: 4510 0034 5643 4000 4006 b45d 0a14 642c E..4VC@.@..]..d,
0x0010: 3495 8d3e deb4 c366 f68a 391c 6bf6 192a 4..>...f..9.k..*
0x0020: 8010 01f5 0335 0000 0101 080a 84aa 3b17 .....5........;.
0x0030: e5e4 44f6 ..D.
22:28:09.749659 e4:5f:01:70:e8:44 > cc:03:d9:ca:a3:ee, ethertype 802.1Q (0x8100), length 106: vlan 100, p 0, ethertype IPv4 (0x0800), (tos 0x10, ttl 64, id 42284, offset 0, flags [DF], proto TCP (6), length 88)
10.20.100.45.57276 > 52.149.141.62.50022: Flags [P.], cksum 0xc279 (correct), seq 715623828:715623864, ack 280003692, win 501, options [nop,nop,TS val 1625559306 ecr 3856883110], length 36
0x0000: 4510 0058 a52c 4000 4006 654f 0a14 642d E..X.,@.@.eO..d-
0x0010: 3495 8d3e dfbc c366 2aa7 8d94 10b0 846c 4..>...f*......l
0x0020: 8018 01f5 c279 0000 0101 080a 60e4 110a .....y......`...
0x0030: e5e3 5da6 9dd1 dab4 bea7 a80c 1852 df93 ..]..........R..
0x0040: b7d9 f99a d74c eda0 5668 2243 fb4d 63b8 .....L..Vh"C.Mc.
0x0050: f335 3ff9 6e14 15a1 .5?.n...
22:28:09.776431 e4:5f:01:70:e9:3a > cc:03:d9:ca:a3:ee, ethertype 802.1Q (0x8100), length 106: vlan 100, p 0, ethertype IPv4 (0x0800), (tos 0x10, ttl 64, id 27677, offset 0, flags [DF], proto TCP (6), length 88)
10.20.100.144.47810 > 52.149.141.62.50022: Flags [P.], cksum 0x7738 (correct), seq 1178195736:1178195772, ack 35976639, win 501, options [nop,nop,TS val 1546394831 ecr 3856883098], length 36
0x0000: 4510 0058 6c1d 4000 4006 9dfb 0a14 6490 E..Xl.@.@.....d.
0x0010: 3495 8d3e bac2 c366 4639 d718 0224 f5bf 4..>...fF9...$..
0x0020: 8018 01f5 7738 0000 0101 080a 5c2c 1ccf ....w8......\,..
0x0030: e5e3 5d9a 2097 9118 ae95 6ec5 4545 e227 ..].......n.EE.'
0x0040: 0982 b5f6 7bea 2754 5509 d794 b6c0 af1a ....{.'TU.......
0x0050: 2be6 52bf 41c1 d103 +.R.A...
22:28:09.776434 cc:03:d9:ca:a3:ee > e4:5f:01:70:e8:44, ethertype 802.1Q (0x8100), length 106: vlan 100, p 0, ethertype IPv4 (0x0800), (tos 0x10, ttl 44, id 3174, offset 0, flags [DF], proto TCP (6), length 88)
52.149.141.62.50022 > 10.20.100.45.57276: Flags [P.], cksum 0x3880 (correct), seq 1:37, ack 36, win 501, options [nop,nop,TS val 3856943154 ecr 1625559306], length 36
0x0000: 4510 0058 0c66 4000 2c06 1216 3495 8d3e E..X.f@.,...4..>
0x0010: 0a14 642d c366 dfbc 10b0 846c 2aa7 8db8 ..d-.f.....l*...
0x0020: 8018 01f5 3880 0000 0101 080a e5e4 4832 ....8.........H2
0x0030: 60e4 110a c9cb 5ea2 0ac5 b74e ff1e 5dcb `.....^....N..].
0x0040: e19b 9555 2fdf f1a2 a6d5 c60b 1074 fd9d ...U/........t..
0x0050: 68ca 9d06 8eb9 8c04 h.......
22:28:09.776734 e4:5f:01:70:e8:44 > cc:03:d9:ca:a3:ee, ethertype 802.1Q (0x8100), length 70: vlan 100, p 0, ethertype IPv4 (0x0800), (tos 0x10, ttl 64, id 42285, offset 0, flags [DF], proto TCP (6), length 52)
10.20.100.45.57276 > 52.149.141.62.50022: Flags [.], cksum 0xb3cf (correct), seq 36, ack 37, win 501, options [nop,nop,TS val 1625559333 ecr 3856943154], length 0
0x0000: 4510 0034 a52d 4000 4006 6572 0a14 642d E..4.-@.@.er..d-
0x0010: 3495 8d3e dfbc c366 2aa7 8db8 10b0 8490 4..>...f*.......
0x0020: 8010 01f5 b3cf 0000 0101 080a 60e4 1125 ............`..%
0x0030: e5e4 4832 ..H2
22:28:09.803353 cc:03:d9:ca:a3:ee > e4:5f:01:70:e9:3a, ethertype 802.1Q (0x8100), length 98: vlan 100, p 0, ethertype IPv4 (0x0800), (tos 0x10, ttl 44, id 55452, offset 0, flags [DF], proto TCP (6), length 80)
52.149.141.62.50022 > 10.20.100.144.47810: Flags [P.], cksum 0x3956 (correct), seq 1:29, ack 36, win 501, options [nop,nop,TS val 3856943181 ecr 1546394831], length 28
0x0000: 4510 0050 d89c 4000 2c06 4584 3495 8d3e E..P..@.,.E.4..>
0x0010: 0a14 6490 c366 bac2 0224 f5bf 4639 d73c ..d..f...$..F9.<
0x0020: 8018 01f5 3956 0000 0101 080a e5e4 484d ....9V........HM
0x0030: 5c2c 1ccf 9fea fe00 459a 04f7 26cc 5af5 \,......E...&.Z.
0x0040: e631 b526 b4e7 06d0 bbe6 bb5e ad8e ea02 .1.&.......^....
22:28:09.803560 e4:5f:01:70:e9:3a > cc:03:d9:ca:a3:ee, ethertype 802.1Q (0x8100), length 70: vlan 100, p 0, ethertype IPv4 (0x0800), (tos 0x10, ttl 64, id 27678, offset 0, flags [DF], proto TCP (6), length 52)
10.20.100.144.47810 > 52.149.141.62.50022: Flags [.], cksum 0x0969 (correct), seq 36, ack 29, win 501, options [nop,nop,TS val 1546394858 ecr 3856943181], length 0
0x0000: 4510 0034 6c1e 4000 4006 9e1e 0a14 6490 E..4l.@.@.....d.
0x0010: 3495 8d3e bac2 c366 4639 d73c 0224 f5db 4..>...fF9.<.$..
0x0020: 8010 01f5 0969 0000 0101 080a 5c2c 1cea .....i......\,..
0x0030: e5e4 484d ..HM
22:28:10.523749 cc:03:d9:ca:a3:ee > e4:5f:01:70:e8:5c, ethertype 802.1Q (0x8100), length 70: vlan 100, p 0, ethertype IPv4 (0x0800), (tos 0x0, ttl 120, id 20238, offset 0, flags [DF], proto TCP (6), length 52)
184.145.157.57.49381 > 10.20.100.43.50022: Flags [S], cksum 0xd549 (correct), seq 3564143126, win 64240, options [mss 1452,nop,wscale 8,nop,nop,sackOK], length 0
0x0000: 4500 0034 4f0e 4000 7806 efab b891 9d39 E..4O.@.x......9
0x0010: 0a14 642b c0e5 c366 d470 8216 0000 0000 ..d+...f.p......
0x0020: 8002 faf0 d549 0000 0204 05ac 0103 0308 .....I..........
0x0030: 0101 0402 ....
--- End Of Stream ---
Packet related to 52.149.141.62 are destinated to the autossh server.
Thanks