{"id":7719,"date":"2026-05-08T16:25:50","date_gmt":"2026-05-08T08:25:50","guid":{"rendered":"https:\/\/www.5x44.cn\/?p=7719"},"modified":"2026-05-08T16:28:41","modified_gmt":"2026-05-08T08:28:41","slug":"tcpdump%e8%bf%87%e6%bb%a4%e5%99%a8","status":"publish","type":"post","link":"https:\/\/www.5x44.cn\/?p=7719","title":{"rendered":"tcpdump\u8fc7\u6ee4\u5668"},"content":{"rendered":"\n<p>tcpdump\u4e3b\u8981\u5206\u4e3a\u4e24\u4e2a\u90e8\u5206\uff0c\u4e00\u662ftcpdump\u672c\u8eab\uff0c\u4e8c\u662f\u8fc7\u6ee4\u5668\uff08pcap-filter\uff09,\u672c\u6587\u4e3b\u8981\u8bb2\u8fc7\u6ee4\u5668\u7528\u6cd5\uff1a<\/p>\n\n\n\n<p><a href=\"https:\/\/www.tcpdump.org\/manpages\/pcap-filter.7.html\">https:\/\/www.tcpdump.org\/manpages\/pcap-filter.7.html<\/a><\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>The&nbsp;<em>filter expression<\/em>&nbsp;consists of one or more&nbsp;<em>primitives<\/em>. Primitives usually consist of an&nbsp;<em>id<\/em>&nbsp;(a name, a number or something slightly more complex, such as a CIDR prefix) preceded by one or more qualifiers. There are three different kinds of qualifier:<\/p>\n\n\n\n<p><em>proto<\/em><\/p>\n\n\n\n<p><em>proto<\/em>&nbsp;qualifiers restrict the match to a particular protocol. (This should not be confused with the&nbsp;<strong>proto<\/strong>&nbsp;type qualifier below.) Possible protocols are:&nbsp;<strong>ether<\/strong>,&nbsp;<strong>link<\/strong>,&nbsp;<strong>wlan<\/strong>,&nbsp;<strong>ip<\/strong>,&nbsp;<strong>ip6<\/strong>,&nbsp;<strong>arp<\/strong>,&nbsp;<strong>tcp<\/strong>,&nbsp;<strong>udp<\/strong>,&nbsp;<strong>sctp<\/strong>,&nbsp;<strong>iso<\/strong>,&nbsp;<strong>isis<\/strong>,&nbsp;<strong>rarp<\/strong>,&nbsp;<strong>decnet<\/strong>,&nbsp;<strong>fddi<\/strong>,&nbsp;<strong>tr<\/strong>,&nbsp;<strong>ppp<\/strong>&nbsp;and&nbsp;<strong>slip<\/strong>. E.g., `<strong>ether src<\/strong>&nbsp;foo&#8217;, `<strong>arp net<\/strong>&nbsp;128.3&#8242;, `<strong>tcp port<\/strong>&nbsp;21&#8242;, `<strong>ip proto<\/strong>&nbsp;ospf&#8217;, `<strong>ether proto<\/strong>&nbsp;0x88CC&#8217;, `<strong>udp portrange<\/strong>&nbsp;7000-7009&#8242;, `<strong>wlan addr2<\/strong>&nbsp;0:2:3:4:5:6&#8242;. If there is no&nbsp;<em>proto<\/em>&nbsp;qualifier, all protocols consistent with the type are assumed. E.g., `<strong>src<\/strong>&nbsp;foo&#8217; means `<strong>(ip6 or ip or arp or rarp) src<\/strong>&nbsp;foo&#8217;, `<strong>proto<\/strong>&nbsp;tcp&#8217; means `<strong>(ip6 or ip) proto<\/strong>&nbsp;tcp&#8217; `<strong>net<\/strong>&nbsp;bar&#8217; means `<strong>(ip6 or ip or arp or rarp) net<\/strong>&nbsp;bar&#8217; and `<strong>port<\/strong>&nbsp;53&#8242; means `<strong>(tcp or udp or sctp) port<\/strong>&nbsp;53&#8242; (note that these examples use invalid syntax to illustrate the principle).<\/p>\n\n\n\n<p><em>dir<\/em><\/p>\n\n\n\n<p><em>dir<\/em>&nbsp;qualifiers specify a particular transfer direction to and\/or from&nbsp;<em>id<\/em>. Possible directions are&nbsp;<strong>src<\/strong>,&nbsp;<strong>dst<\/strong>,&nbsp;<strong>src or dst<\/strong>,&nbsp;<strong>src and dst<\/strong>,&nbsp;<strong>ra<\/strong>,&nbsp;<strong>ta<\/strong>,&nbsp;<strong>addr1<\/strong>,&nbsp;<strong>addr2<\/strong>,&nbsp;<strong>addr3<\/strong>, and&nbsp;<strong>addr4<\/strong>. E.g., `<strong>src<\/strong>&nbsp;foo&#8217;, `<strong>dst net<\/strong>&nbsp;128.3&#8242;, `<strong>src or dst port<\/strong>&nbsp;ftp-data&#8217;. If there is no dir qualifier, `<strong>src or dst<\/strong>&#8216; is assumed. The&nbsp;<strong>ra<\/strong>,&nbsp;<strong>ta<\/strong>,&nbsp;<strong>addr1<\/strong>,&nbsp;<strong>addr2<\/strong>,&nbsp;<strong>addr3<\/strong>, and&nbsp;<strong>addr4<\/strong>&nbsp;qualifiers are only valid for IEEE 802.11 Wireless LAN link layers.<\/p>\n\n\n\n<p><em>type<\/em><\/p>\n\n\n\n<p><em>type<\/em>&nbsp;qualifiers say what kind of thing the id name or number refers to. Possible types are&nbsp;<strong>host<\/strong>,&nbsp;<strong>net<\/strong>,&nbsp;<strong>proto<\/strong>,&nbsp;<strong>port<\/strong>,&nbsp;<strong>portrange<\/strong>,&nbsp;<strong>protochain<\/strong>&nbsp;and&nbsp;<strong>gateway.<\/strong>&nbsp;E.g., `<strong>host<\/strong>&nbsp;foo&#8217;, `<strong>net<\/strong>&nbsp;128.3&#8242;, `<strong>port<\/strong>&nbsp;20&#8242;, `<strong>portrange<\/strong>&nbsp;6000-6008&#8242;, `<strong>proto&nbsp;<\/strong>17&#8242;. If there is no type qualifier,&nbsp;<strong>host<\/strong>&nbsp;is assumed.<\/p>\n<\/blockquote>\n\n\n\n<p>\u4e3b\u8981\u662f\u8bf4\u8fc7\u6ee4\u5668\u8868\u8fbe\u5f0f\u7531\u4e00\u4e2a\u6216\u591a\u4e2a\u57fa\u5143\u7ec4\u6210\u3002\u57fa\u5143\u901a\u5e38\u662f\u7531\u4e00\u4e2a\u6216\u591a\u4e2a\u4fee\u9970\u7b26\u524d\u5bfc\u7684id(\u53ef\u4ee5\u662f\u540d\u5b57\u3001\u6570\u5b57\u6216\u662f\u4e00\u4e9b\u66f4\u590d\u6742\u7684\u5185\u5bb9\uff0c\u5982\uff1aCIDR\u524d\u7f00)\u7ec4\u6210\u3002<\/p>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>tcpdump\u4e3b\u8981\u5206\u4e3a\u4e24\u4e2a\u90e8\u5206\uff0c\u4e00\u662ftcpdump\u672c\u8eab\uff0c\u4e8c\u662f\u8fc7\u6ee4\u5668\uff08pcap-filter\uff09,\u672c\u6587\u4e3b\u8981\u8bb2\u8fc7\u6ee4\u5668\u7528\u6cd5\uff1a https:\/\/www.tcpdump.o&#8230;<\/p>\n<p class=\"read-more\"><a class=\"btn btn-default\" href=\"https:\/\/www.5x44.cn\/?p=7719\"> Read More<span class=\"screen-reader-text\">  Read More<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[8,25],"tags":[],"class_list":["post-7719","post","type-post","status-publish","format-standard","hentry","category-it","category-25"],"_links":{"self":[{"href":"https:\/\/www.5x44.cn\/index.php?rest_route=\/wp\/v2\/posts\/7719","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.5x44.cn\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.5x44.cn\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.5x44.cn\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.5x44.cn\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=7719"}],"version-history":[{"count":6,"href":"https:\/\/www.5x44.cn\/index.php?rest_route=\/wp\/v2\/posts\/7719\/revisions"}],"predecessor-version":[{"id":7725,"href":"https:\/\/www.5x44.cn\/index.php?rest_route=\/wp\/v2\/posts\/7719\/revisions\/7725"}],"wp:attachment":[{"href":"https:\/\/www.5x44.cn\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=7719"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.5x44.cn\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=7719"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.5x44.cn\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=7719"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}