?
Solved

TCPDump Examples

Posted on 2014-03-25
9
Medium Priority
?
426 Views
Last Modified: 2014-03-31
Heyas,

I can't seem to find a decent example of how to use the tcpdump with the following parameters.

tcpdump [ipaddress] [interface] [port]

Any assistance is welcome.

Thank you.
0
Comment
Question by:Zack
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 3
9 Comments
 
LVL 48

Accepted Solution

by:
Tintin earned 1100 total points
ID: 39955225
tcpdump -i eth0 port 80 src 10.1.1.1
0
 
LVL 19

Expert Comment

by:simon3270
ID: 39955508
On RedHat I need

     tcpdump -i eth0 port 80 and src 10.1.1.1
0
 
LVL 19

Expert Comment

by:simon3270
ID: 39955594
You can make more complex statements too:

    tcpdump -i eth0 port 80 and \( src 10.10.10.101 or dst 10.10.10.102 \)
0
Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 

Author Closing Comment

by:Zack
ID: 39964716
Thank you for the info.
0
 
LVL 19

Expert Comment

by:simon3270
ID: 39964897
Just out of interest, which OS are you doing this on?

Thanks,
Simon
0
 

Author Comment

by:Zack
ID: 39965509
Knoppix
0
 
LVL 19

Expert Comment

by:simon3270
ID: 39966480
I think you may have accepted the wrong answer.  On Knoppix 7.2:

knoppix@Microknoppix:~$ sudo tcpdump -i eth0 port 80 src 10.1.1.1
tcpdump: syntax error
knoppix@Microknoppix:~$ sudo tcpdump -i eth0 port 80 and src 10.1.1.1
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on eth0, link-type EN10MB (Ethernet), capture size 65535 bytes

Open in new window


It needs the "and".
0
 

Author Comment

by:Zack
ID: 39966700
It worked on the system I was on at the time, I was remotely logged into a Knoppix machine via SSH.
0
 
LVL 19

Expert Comment

by:simon3270
ID: 39966718
OK, no problem.
0

Featured Post

What is SQL Server and how does it work?

The purpose of this paper is to provide you background on SQL Server. It’s your self-study guide for learning fundamentals. It includes both the history of SQL and its technical basics. Concepts and definitions will form the solid foundation of your future DBA expertise.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Fine Tune your automatic Updates for Ubuntu / Debian
Google Drive is extremely cheap offsite storage, and it's even possible to get extra storage for free for two years.  You can use the free account 15GB, and if you have an Android device..when you install Google Drive for the first time it will give…
Learn how to get help with Linux/Unix bash shell commands. Use help to read help documents for built in bash shell commands.: Use man to interface with the online reference manuals for shell commands.: Use man to search man pages for unknown command…
How to Install VMware Tools in Red Hat Enterprise Linux 6.4 (RHEL 6.4) Step-by-Step Tutorial
Suggested Courses
Course of the Month9 days, 10 hours left to enroll

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question