茫茫網海中的冷日
         
茫茫網海中的冷日
發生過的事,不可能遺忘,只是想不起來而已!
 恭喜您是本站第 1733078 位訪客!  登入  | 註冊
主選單

Google 自訂搜尋

Goole 廣告

隨機相片
PIMG_00073.jpg

授權條款

使用者登入
使用者名稱:

密碼:


忘了密碼?

現在就註冊!

小企鵝開談 : [教學]如何抓取主機現有連線的封包?

發表者 討論內容
冷日
(冷日)
Webmaster
  • 註冊日: 2008/2/19
  • 來自:
  • 發表數: 15773
[轉貼]tcpdump: Monitor ALL eth1 Traffic Except My Own SSH Session
tcpdump: Monitor ALL eth1 Traffic Except My Own SSH Session

I‘m using tcpdump to dump, debug and monitor traffic on a network. However, there is lots of noise and I would like to exclude ssh from my dumps. How do I monitor all traffic except my ssh session?

The tcpdump command displays out the headers of packets on a network interface that match the boolean expression. In other words you can use boolean expression to drop ssh traffic from dumping and monitoring operation using the following syntax:
tcpdump -i eth1  -s 1500 port not 22

You can skip additional ports too:
tcpdump -i eth1  -s 1500 port not 22 and port not 53

You can also use ip or hostname:
tcpdump -i eth1 port not 22 and host 1.2.3.4

SEE ALSO:
man tcpdump

原文出處:tcpdump: Monitor ALL eth1 Traffic Except My Own SSH Session - nixCraft
前一個主題 | 下一個主題 | | | |

討論串




Powered by XOOPS 2.0 © 2001-2008 The XOOPS Project|