Improve company productivity with a Business Account.Sign Up

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 1974
  • Last Modified:

WireShark - Capture Filter - FIN packets only

Hi All,

I'm troubleshooting a WAN Telnet disconnect problem that only occurs after 1-2 hours of inactivity.  The terminal emulation software vendor tells me I need to look for "FIN" packets for finding what device is terminating the connection.  Since there will be so much traffic in 1-2 hours, I'd like to just capture any packets that contain "FIN".

Can you help me with building the Capture Filter to accomplish this?

Thanks,
Dave
0
dsstao
Asked:
dsstao
1 Solution
 
Otto_NCommented:
'tcp[tcpflags] & tcp-fin != 0'  should do the trick (without the quotes, of course).

However, there can be quite a lot of TCP connections closing.  If you want to capture only packets to and from a particular host, add 'and host 10.10.10.1' to the capture filter.
0
 
dsstaoAuthor Commented:
Thank you, YDM
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Improve Your Query Performance Tuning

In this FREE six-day email course, you'll learn from Janis Griffin, Database Performance Evangelist. She'll teach 12 steps that you can use to optimize your queries as much as possible and see measurable results in your work. Get started today!

Tackle projects and never again get stuck behind a technical roadblock.
Join Now