• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 1083
  • Last Modified:

TCPDUMP: How do I filter an arp message by checking for equality with arp's hexadecimal value of 0806?

I've spent the last hour trying to figure this challenge out.  I know I can filter out by name but would like to also know how to by hexadecimal value.

I have a capture file and would like to filter arp by its hexadecimal value 0806?  Any additional explanation will be appreciated.  Thanks.
1 Solution
The pattern to capture specific bytes from a protocol header in tcpdump is
proto [ offset : length ]

You know that the ethernet header has the 2-byte protocol field after the first 12 bytes (destination and source). So match them with

Then apply the bitwise or comparison operations you need; in your case the whole field must have a specific value.

But watch out the presence of LLC when filtering some protocols, in those cases better using the protocol name.
jeffw22Author Commented:

Featured Post

Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Tackle projects and never again get stuck behind a technical roadblock.
Join Now