Прошу прощения, что именно будем искать?
вот фрагмент вывода tcpdump -i eth1
17:33:24.309238 IP 192.168.1.102.35431 > 172.31.3.252.cisco-sccp: Flags , seq 1007490339, win 16384, options [mss 1456,nop,wscale 0,nop,nop,TS val 58469117 ecr 0], length 0
17:33:24.323364 IP 172.27.149.252.63768 > 202.12.27.33.domain: 45742 [1au] PTR? 250.3.31.172.in-addr.arpa. (54)
17:33:24.323602 IP 172.27.149.254 > 172.27.149.252: ICMP host 202.12.27.33 unreachable, length 36
17:33:24.740557 IP 172.27.149.252.54476 > 128.8.10.90.domain: 6415 [1au] PTR? 254.149.27.172.in-addr.arpa. (56)
17:33:24.748418 IP 172.27.149.5.35569 > 172.31.3.251.cisco-sccp: Flags [P.], seq 64:84, ack 229, win 17328, options [nop,nop,TS val 464122 ecr 3350054022], length 20
17:33:24.751471 IP 172.27.149.5.35569 > 172.31.3.251.cisco-sccp: Flags [P.], seq 84:104, ack 229, win 17328, options [nop,nop,TS val 464123 ecr 3350054022], length 20
17:33:33.761038 IP 172.27.149.252.60942 > 128.8.10.90.domain: 43195 [1au] PTR? 5.149.27.172.in-addr.arpa. (54)
17:33:33.761282 IP 172.27.149.254 > 172.27.149.252: ICMP host 128.8.10.90 unreachable, length 36
17:33:33.915301 STP 802.1d, Config, Flags [none], bridge-id 8095.b8:be:bf:a0:cc:00.8013, length 43
17:33:34.251098 DTPv1, length 38