1
|
tcpdump -i eth0 icmp
|
1
2
3
4
5
6
7
|
[root@VLT ~]
# tcpdump -i eth0 icmp
tcpdump: verbose output suppressed, use -
v
or -vv
for
full protocol decode
listening on eth0, link-
type
EN10MB (Ethernet), capture size 65535 bytes
11:15:41.138115 IP 172.16.x.xxx > 172.30.x.xxx: ICMP
echo
request,
id
1,
seq
17, length 40
11:15:41.138149 IP 172.30.x.xxx > 172.16.x.xxx: ICMP
echo
reply,
id
1,
seq
17, length 40
11:15:42.139969 IP 172.16.x.xxx > 172.30.x.xxx: ICMP
echo
request,
id
1,
seq
18, length 40
11:15:42.139997 IP 172.30.x.xxx > 172.16.x.xxx: ICMP
echo
reply,
id
1,
seq
18, length 40
|
1
|
tcpdump -i eth0 -vnn host 10.10.10.122
|
1
|
tcpdump -i eth0 -vnn net 10.10.10.0
/24
|
1
|
tcpdump -i eth0 -vnn port 22
|
1
|
tcpdump -i eth0 -vnn udp
|
1
|
tcpdump -i eth0 -vnn icmp
|
1
|
tcpdump -i eth0 -vnn arp
|
1
|
tcpdump -i eth0 -vnn ip
|
1
|
tcpdump -i eth0 -vnn src host 10.10.10.122
|
1
|
tcpdump -i eth0 -vnn dst host 10.10.10.122
|
1
|
tcpdump -i eth0 -vnn src port 22
|
1
|
tcpdump -i eth0 -vnn src host 10.10.10.253 and dst port 22
|
1
|
tcpdump -i eth0 -vnn src host 10.10.10.122 or port 22
|
1
|
tcpdump -i eth0 -vnn src host 10.10.10.122 and not port 22
|
1
|
tcpdump -i eth0 -vnn \( src host 10.10.10.2 and dst port 22 \) or \( src host 10.10.10.65 and dst port 80 \)
|
1
|
tcpdump -i eth0 -vnn
'src host 10.10.10.59 and dst port 22'
or
' src host 10.10.10.68 and dst port 80 '
|
1
|
tcpdump –i eth0 -vnn -w
/tmp/fil1
-c 100
|
1
|
tcpdump –i eth0 -vnn -r
/tmp/fil1
tcp
|
1
|
tcpdump –i eth0 -vnn -r
/tmp/fil1
host 10.10.10.58
|