Filter tcpdump by IP: Hosts, Direction, Subnets, and Ports
When a packet capture is full of traffic you don't care about, narrow it with a capture filter. For an IP address, the key distinction is whether you want traffic in both directions, only packets from the address, or only packets going to it. sudo tcpdump -nn -i eth0 'host 192.0.2.25' This captures packets where 192.0.2.25 is either the source or destination. Replace the example address and interface with the ones relevant to your system. An IP filter only sees packets that reach the interface you selected.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in