Packet Captures: Difference between revisions
m
→Capture Filter Primitives: table
m (→TCP Flags: m) |
m (→Capture Filter Primitives: table) |
||
Line 357:
====Capture Filter Primitives====
{| class="wikitable"
|-
! Filter !! Description
|-
|-
[tcp|udp] [src|dst] port <port> Matches TCP or UDP packets sent to/from port▼
|-
less <length> Matches packets less than or equal to length▼
|-
(ether|ip|ip6) proto <protocol> Matches an Ethernet, IPv4, or IPv6 protocol▼
| [src|dst] net <network>/<len> || Matches packets to or from an endpoint residing in network
(ether|ip) broadcast Matches Ethernet or IPv4 broadcasts▼
|-
(ether|ip|ip6) multicast Matches Ethernet, IPv4, or IPv6 multicasts▼
type (mgt|ctl|data) [subtype <subtype>] Matches 802.11 frames based on type and optional subtype▼
|-
vlan [<vlan>] Matches 802.1Q frames, optionally with a VLAN ID of vlan▼
| [tcp|udp] [src|dst] portrange <p1>-<p2> || Matches TCP or UDP packets to/from a port in the given range
mpls [<label>] Matches MPLS packets, optionally with a label of label▼
|-
<expr> <relop> <expr> Matches packets by an arbitrary expression▼
|-
| greater <length> || Matches packets greater than or equal to length
|-
|-
|-
|-
▲
|-
|-
|-
|}
====Command Line Options====
|