Hi When I start arpwatch or tcpdump the Ethernet card eth0 goes into promiscuous mode but I cannot see it with ifconfig eth0 or ip link show. The only way I can see it is when I looked at dmesg. Ifconfig uses the old style IOFLAG way to determine this but looking into ip code this is supposed to work even with newer kernels (I'm on 2.6.17 now with the latest iproute package) I found these links about the issue http://www.tcpdump.org/lists/workers/2001/01/msg00184.html http://lists.virus.org/bugtraq-0207/msg00363.html Radek -- Radek Vokál <rvokal@xxxxxxxxxx> _______________________________________________ LARTC mailing list LARTC@xxxxxxxxxxxxxxx http://mailman.ds9a.nl/cgi-bin/mailman/listinfo/lartc