CentOS tcpdump to capture only a specific protocol.

Hey guys,
So trying to figure out if there is a way in tcpdump to only capture 2 protocols.
We are trying to capture SIP and RTP.  
We cannot really specify port since the RTP can be 10000-20000

Is there a way to tell it something like protocol=sip && protocol=rtp?

or does tcpdump not have the inteligence to know what protocols go with what ports?

If it doesn't how could i write a filter that inclues 5060 and 10000-20000

Who is Participating?
you can do something like

tcpdump -i eth0 udp port 5060 or udp portrange 10000-20000
tsukrawAuthor Commented:
Thank you
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.