tsukraw
asked on
CentOS tcpdump to capture only a specific protocol.
Hey guys,
So trying to figure out if there is a way in tcpdump to only capture 2 protocols.
We are trying to capture SIP and RTP.
We cannot really specify port since the RTP can be 10000-20000
Is there a way to tell it something like protocol=sip && protocol=rtp?
or does tcpdump not have the inteligence to know what protocols go with what ports?
If it doesn't how could i write a filter that inclues 5060 and 10000-20000
Thanks!
So trying to figure out if there is a way in tcpdump to only capture 2 protocols.
We are trying to capture SIP and RTP.
We cannot really specify port since the RTP can be 10000-20000
Is there a way to tell it something like protocol=sip && protocol=rtp?
or does tcpdump not have the inteligence to know what protocols go with what ports?
If it doesn't how could i write a filter that inclues 5060 and 10000-20000
Thanks!
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER