tcpdump   wireshark


tcpdump -i br0 -nn host 192.168.1.12 and port 80  -w /tmp/baidu.pcap 


-nn:直接以 IP 及 port number 显示,而非主机名与服务名称


tcpdump -r /tmp/baidu.pcap -nn host 192.168.1.12


tcpdump -i eth0 -vnn src host 192.168.1.12

tcpdump -i eth0 -vnn dst host 192.168.1.12

tcpdump -i eth0 -vnn udp

tcpdump -i eth0 -vnn icmp

tcpdump -i eth0 -vnn arp

tcpdump -i eth0 -vnn ip


yum install scapy