Ethereal-users: Re: [Ethereal-users] Cannot filter on dst net?
Note: This archive is from the project's previous web site, ethereal.com. This list is no longer active.
From: Jeff Davis <jdavis@xxxxxxxxxxxxxxxxxx>
Date: Thu, 17 Nov 2005 13:34:55 -0800
|
Yup - that did it :) I was trying to do a capture filter - basically capture all outbound bogon traffic to trace which host was infected with bagle - btw if there's a better way to do this please let me know. Yeah part of my problem was using capture syntax in the display filter. Mea Culpa. Thanks Wakefield, Thad M. wrote: Try: (tcp and (dst net 0 or ...)) Thad-----Original Message----- From: ethereal-users-bounces@xxxxxxxxxxxx [mailto:ethereal-users-bounces@xxxxxxxxxxxx] On Behalf Of Jack Jackson Sent: Thursday, November 17, 2005 3:23 PM To: Ethereal user support Subject: Re: [Ethereal-users] Cannot filter on dst net? I'm still not sure what you are trying to do - capture filter or display filter? A capture filter of: dst net 192.0.0.0 mask 255.0.0.0 works for me. The tcpdump man page at http://www.ethereal.com/docs/man-pages/tcpdump.8.html in the description for the 'net' options says "(see networks(4) for details)". I can't find that at www.ethereal.com and the ones I found by Googling aren't very descriptive, so I'm not sure what is the legal syntax for 'net'. At 08:53 AM 11/17/2005, Jeff Davis wrote: -- Jefferson K. Davis Technology and Information Systems Manager Standard School District 1200 North Chester Ave Bakersfield, CA 93308 USA 661-392-2110 ext 120 |
- References:
- RE: [Ethereal-users] Cannot filter on dst net?
- From: Wakefield, Thad M.
- RE: [Ethereal-users] Cannot filter on dst net?
- Prev by Date: RE: [Ethereal-users] Cannot filter on dst net?
- Next by Date: Re: [Ethereal-users] ss7 monitoring query
- Previous by thread: RE: [Ethereal-users] Cannot filter on dst net?
- Next by thread: [Ethereal-users] Follow TCP Stream strangeness
- Index(es):