1. tcpdump Command
tcpdump -i any -s 0 -U -w /filepah
2. Wireshark filter usage
ip.addr == 192.168.0.1 //filter Source or Destination IP address
ip.src == 192.168.0.1 //filter source IPip.dst == 192.168.0.1 //filter destination IP
tcp.port == 80 //filter tcp port
tcp.port != 80 //filter tcp port
tcp.port == 80 and ip.src == 192.168.0.1
udp.port == 12345 or ip.dst == 192.168.0.1
3. tcp 握手