[Webinar] Streamline your web hosting managementRegister Today

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 1960
  • Last Modified:

WireShark - Capture Filter - FIN packets only

Hi All,

I'm troubleshooting a WAN Telnet disconnect problem that only occurs after 1-2 hours of inactivity.  The terminal emulation software vendor tells me I need to look for "FIN" packets for finding what device is terminating the connection.  Since there will be so much traffic in 1-2 hours, I'd like to just capture any packets that contain "FIN".

Can you help me with building the Capture Filter to accomplish this?

Thanks,
Dave
0
dsstao
Asked:
dsstao
1 Solution
 
Otto_NCommented:
'tcp[tcpflags] & tcp-fin != 0'  should do the trick (without the quotes, of course).

However, there can be quite a lot of TCP connections closing.  If you want to capture only packets to and from a particular host, add 'and host 10.10.10.1' to the capture filter.
0
 
dsstaoAuthor Commented:
Thank you, YDM
0

Featured Post

Evaluating UTMs? Here's what you need to know!

Evaluating a UTM appliance and vendor can prove to be an overwhelming exercise.  How can you make sure that you're getting the security that your organization needs without breaking the bank? Check out our UTM Buyer's Guide for more information on what you should be looking for!

Tackle projects and never again get stuck behind a technical roadblock.
Join Now