Using TCPDump Filter Expression

转载 2013年12月05日 21:42:43

Using TCPDump Filter Expressions

Table 1: Examples of TCPDump Filter Expressions

Example

Result

tcp port 80

Sniffs packets on TCP port 80.

port 80

Sniffs packets on TCP or UDP port 80.

ip

Sniffs the IP protocol.

tcp

Sniffs the TCP protocol.

dst #.#.#.#

Sniffs the destination IP address specified, where #.#.#.# is a valid IP address.

src #.#.#.#

Sniffs the source IP address specified, where #.#.#.# is a valid IP address.

port 80 or port 443

Sniffs on port 80 or port 443.

src #.#.#.# and dst #.#.#.#

Sniffs the source and destination IP addresses or hosts specified, where each #.#.#.# represents a valid IP address.

tcp port 80 or port 443 and dst #.#.#.# and src #.#.#.#

This example shows how to specify multiple parameters to create a filter that sniffs on TCP port 80, or on TCP or UDP port 443, and on the destination and source ports, where each #.#.#.# represents a valid IP address.

For more information about TCPDump Filter Expressions, visit the following Web site:http://www.tcpdump.org/tcpdump_man.html

http://www.juniper.net/techpubs/en_US/uac/topics/reference/general/uac-troubleshooting-tcp-dump-expressions.html

相关文章推荐

lintcode :expression expand using C++

Given an expression s includes numbers, letters and brackets. Number represents the number of repeti...

More about using regular expression in notepad++

/*by Jiangong SUN*/ I've written a blog in introducing regular expressions in notepad++, but it's k...

CASE: Match multiple lines of text using Regular Expression.

It was the case raised by my friend Wind this afternoon.           He wants to use C# Regex Class ...
  • Hisgend
  • Hisgend
  • 2011年09月07日 18:49
  • 116

Search across multiple lines using regular expression in VIM

Search across multiple lines (come from http://vim.wikia.com/wiki/Search_across_multiple_lines) ...
  • oygy
  • oygy
  • 2012年09月20日 09:25
  • 776

Oracle Rules Manager 和 Oracle Expression Filter 组件 说明

一.Rules Manager 和 Expression Filter 组件说明 在说明之前,我们先用如下SQL查看一下DB中的组件:SQL> col comp_id for a15SQL> col ...

libpcap/tcpdump filter 语法

libpcap/tcpdump filter syntax 语法: type type qualifiers say what kind of thing the id name or ...
内容举报
返回顶部
收藏助手
不良信息举报
您举报文章:Using TCPDump Filter Expression
举报原因:
原因补充:

(最多只允许输入30个字)