TCPDUMP Command Line Options

Networking, Packet Analysis · notes

Voir tous les documents en réseaux

TCPDUMP

packetlife.net

Command Line Options

-A

Print frame payload in ASCII

-q

Quick output

-c <count> Exit after capturing count packets

-r <file>

Read packets from file

-D

-e

List available interfaces

Print link-level headers

-F <file>

Use file as the filter expression

-s <len>

Capture up to len bytes per packet

-S

-t

Print absolute TCP sequence numbers

Don't print timestamps

-G <n>

Rotate the dump file every n seconds

-v[v[v]]

Print more verbose output

Publicité

-i <iface> Specifies the capture interface

-w <file> Write captured packets to file

-K

-L

-n

-p

Don't verify TCP checksums

List data link types for the interface

-x

-X

Print frame payload in hex

Print frame payload in hex and ASCII

Don't convert addresses to names

-y <type>

Specify the data link type

Don't capture in promiscuous mode

-Z <user>

Drop privileges from root to user

Capture Filter Primitives

[src|dst] host <host>

Matches a host as the IP source, destination, or either

ether [src|dst] host <ehost>

Matches a host as the Ethernet source, destination, or either

gateway host <host>

Matches packets which used host as a gateway

[src|dst] net <network>/<len>

Publicité

Matches packets to or from an endpoint residing in network

[tcp|udp] [src|dst] port <port>

Matches TCP or UDP packets sent to/from port

[tcp|udp] [src|dst] portrange <p1>-<p2> Matches TCP or UDP packets to/from a port in the given range

less <length>

greater <length>

Matches packets less than or equal to length

Matches packets greater than or equal to length

(ether|ip|ip6) proto <protocol>

Matches an Ethernet, IPv4, or IPv6 protocol

(ether|ip) broadcast

Matches Ethernet or IPv4 broadcasts

(ether|ip|ip6) multicast

Matches Ethernet, IPv4, or IPv6 multicasts

type (mgt|ctl|data) [subtype <subtype>] Matches 802.11 frames based on type and optional subtype

vlan [<vlan>]

mpls [<label>]

Matches 802.1Q frames, optionally with a VLAN ID of vlan

Matches MPLS packets, optionally with a label of label

<expr> <relop> <expr>

Matches packets by an arbitrary expression

Protocols

Modifiers

Examples

arp

ip6

Publicité

slip

! or not

udp dst port not 53

UDP not bound for port 53

ether

link

ppp

tcp

tr

&& or and

host 10.0.0.1 && host 10.0.0.2

Traffic between these hosts

|| or or

tcp dst port 80 or 8080

Packets to either TCP port

radio

udp

rarp

wlan

icmp-echoreply

icmp-routeradvert

icmp-tstampreply

ICMP Types

TCP Flags

icmp-unreach

icmp-routersolicit

Publicité

icmp-ireq

tcp-urg

tcp-rst

icmp-sourcequench

icmp-timxceed

icmp-ireqreply

tcp-ack

tcp-syn

icmp-redirect

icmp-paramprob

icmp-maskreq

tcp-psh

tcp-fin

icmp-echo

icmp-tstamp

icmp-maskreply

by Jeremy Stretch

v2.0

fddi

icmp

ip