Solved

WireShark - Capture Filter - FIN packets only

Posted on 2010-11-10
2
1,859 Views
Last Modified: 2012-05-10
Hi All,

I'm troubleshooting a WAN Telnet disconnect problem that only occurs after 1-2 hours of inactivity.  The terminal emulation software vendor tells me I need to look for "FIN" packets for finding what device is terminating the connection.  Since there will be so much traffic in 1-2 hours, I'd like to just capture any packets that contain "FIN".

Can you help me with building the Capture Filter to accomplish this?

Thanks,
Dave
0
Comment
Question by:dsstao
2 Comments
 
LVL 14

Accepted Solution

by:
Otto_N earned 500 total points
Comment Utility
'tcp[tcpflags] & tcp-fin != 0'  should do the trick (without the quotes, of course).

However, there can be quite a lot of TCP connections closing.  If you want to capture only packets to and from a particular host, add 'and host 10.10.10.1' to the capture filter.
0
 
LVL 1

Author Closing Comment

by:dsstao
Comment Utility
Thank you, YDM
0

Featured Post

Network it in WD Red

There's an industry-leading WD Red drive for every compatible NAS system to help fulfill your data storage needs. With drives up to 8TB, WD Red offers a wide array of solutions for customers looking to build the biggest, best-performing NAS storage solution.  

Join & Write a Comment

Suggested Solutions

Title # Comments Views Activity
Cisco NAC Appliance 4 38
Automation tools 2 112
Win 2012 WDS Server 6 53
snmp error in packet. reason noaccess 30 74
Is your computer hacked? learn how to detect and delete malware in your PC
Join Greg Farro and Ethan Banks from Packet Pushers (http://packetpushers.net/podcast/podcasts/pq-show-93-smart-network-monitoring-paessler-sponsored/) and Greg Ross from Paessler (https://www.paessler.com/prtg) for a discussion about smart network …
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…

728 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

8 Experts available now in Live!

Get 1:1 Help Now