Tcpdump Packet Filtering
Helpful Tcpdump Filters
Filter
Result
Examples of Common Filters
sudo tcpdump -i eth0 host 172.16.146.2sudo tcpdump -i eth0 src host 172.16.146.2sudo tcpdump -i eth0 tcp src port 80sudo tcpdump -i eth0 dest net 172.16.146.0/24sudo tcpdump -i eth0 udpsudo tcpdump -i eth0 proto 17sudo tcpdump -i eth0 tcp port 443sudo tcpdump -i eth0 portrange 0-1024sudo tcpdump -i eth0 less 64sudo tcpdump -i eth0 greater 500
Combining Filters with AND and OR
AND and ORPre-Capture vs. Post-Capture Processing
Interpreting Tips and Tricks
ASCII Mode with -A
-APiping Output to Grep
Advanced Packet Filtering Using TCP Flags
Protocol RFC Links
Protocol
RFC
Last updated