>You can get ipgrab at http;//www.borella.net/mike >I added ESP, AH and IKE in March but just updated >them recently, so fruther testing and reports would >be welcome. KAME (ftp.kame.net) includes ESP/AH/IKE support in tcpdump, as well as ESP decoding in limited cases (you need to supply encryption key and algorithms on the command line) To what extent do you decode IKE? itojun