So trying to figure out if there is a way in tcpdump to only capture 2 protocols.
We are trying to capture SIP and RTP.  
We cannot really specify port since the RTP can be 10000-20000

Is there a way to tell it something like protocol=sip && protocol=rtp?

or does tcpdump not have the inteligence to know what protocols go with what ports?

If it doesn't how could i write a filter that inclues 5060 and 10000-20000

you can do something like

tcpdump -i eth0 udp port 5060 or udp portrange 10000-20000
tsukrawAuthor Commented:
Thank you
