May 2017
Beginner
552 pages
28h 47m
English
The port key displays only the packets sent to or from a given port:
$ tcpdump -r /tmp/tcpdump.raw port http reading from file /tmp/tcpdump.raw, link-type EN10MB (Ethernet) 10:36:50.586005 IP 192.168.1.44.59154 > ord38s04-in-f3.1e100.net.http: Flags [.], ack 3779320903, win 431, options [nop,nop,TS val 2061350532 ecr 3014589802], length 0 10:36:50.586007 IP ord38s04-in-f3.1e100.net.http > 192.168.1.44.59152: Flags [.], ack 1, win 350, options [nop,nop,TS val 3010640112 ecr 2061270277], length 0