举例:
保存到文件
tcpdump -w xxx.cap(默认抓取eth0的包)
抓eth1的包
tcpdump -i eth1 -w /tmp/xxx.cap
抓到完成的数据包(默认只抓前68字节)
tcpdump -s 0 -w /tmp/xxx.cap
抓192.168.1.123的包
tcpdump -i eth 1 host 192.168.1.123 -w /tmp/xxx.cap
抓取80端口的包
tcpdump -i eth1 port 80 -w /tmp/xxx.cap
抓取范围内的端口
tcpdump -i eth1 portrange 80-82 -w /tmp/xxx.cap
抓192.168.1.123 的 icmp的包
tcpdump -i eth1 host 192.168.1.123 and icmp -w /tmp/xxx.cap
抓192.168.1.123的80端口和22端口之外的其他端口的包
tcpdump -i eth1 host 192.168.1.123 and ! port 80 and ! port 22 -w /tmp/xxx.cap
抓vlan 1的包
tcpdump -i eth1 port 80 and vlan 1 -w /tmp/xxx.cap
抓pppoe的密码
tcpdump -i eth1 pppoes -w /tmp/xxx.cap
已100m大小分割保存文件,超过100m另开一个文件
tcpdump -i eth1 -C 100m -w /tmp/xxx.cap
抓1000个包后退出
tcpdump -i eth1 -c 1000 -w /tmp/xxx.cap