有时候想抓个包,比如 53 端口的包:
tcpdump -i eth1 port 53
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on eth1, link-type EN10MB (Ethernet), capture size 65535 bytes
14:19:01.545430 IP testsvr1_in.50145 > 12.12.12.12.domain: 12328+ PTR? 6.2.66.100.in-addr.arpa. (43)
14:19:01.545631 IP testsvr1_in.40356 > 12.12.12.12.domain: 42024+ PTR? 7.64.240.10.in-addr.arpa. (44)
14:19:01.547521 IP 12.12.12.12.domain > testsvr1_in.50145: 12328 NXDomain* 0/1/0 (97)
14:19:01.549520 IP 12.12.12.12.domain > testsvr1_in.40356: 42024 NXDomain* 0/1/0 (91)
14:19:01.553631 IP testsvr1_in.42410 > 12.12.12.12.domain: 39216+ PTR? 9.138.123.10.in-addr.arpa. (45)
14:19:01.553890 IP 12.12.12.12.domain > testsvr1_in.42410: 39216 NXDomain* 0/1/0