This is our old Q&A Site. Please post any new questions and answers at

Example of my filter: "not broadcast and not multicast and not src net"

and don't want to capture data from IP range: - and -

asked 27 Apr '16, 04:14

myszoor's gravatar image

accept rate: 0%

edited 27 Apr '16, 04:16

If you want to exclude subnet ranges completely you'll need to explicitly exclude both source and destination IP ranges, e.g.:

not (ip.src== or ip.dst== and not (ip.src== or ip.dst==

permanent link

answered 27 Apr '16, 04:29

Jasper's gravatar image

Jasper ♦♦
accept rate: 18%


  • the OP asks for a capture filter so the syntax is not the correct one; in capture filter, not net would cover both src and dst but he's asked for src only (data from IP range)

  • the OP has specially asked for a range so won't do as, and should be let through unless he's made a mistake.

(27 Apr '16, 04:39) sindy

right... my bad about the capture filter syntax, I read the question too fast I guess. :-)

The question wording is a bit unspecific - he gives an example with broadcast and multicast and a src range and say "AND don't want to..." which lead me to assume that he want's to expand the example. I assumed also that the ranges should not appear at all, so a src filter only wouldn't do.

And yes, I assumed the full range was in question as it makes almost no sense at all to leave two /32 in there, especially the .0.0 which is the net address and should never been seen anyway for that range.

(27 Apr '16, 04:54) Jasper ♦♦

The simple answer would be not net and not net but that would also exclude the ranges - and -

If you do want to see traffic in the x.x.0.0/24 subnets, then you'll have to "or" in those networks, e.g. ... or net or net

permanent link

answered 27 Apr '16, 04:43

grahamb's gravatar image

grahamb ♦
accept rate: 22%


The simple answer would be not net and not net but that would also exclude the ranges - and -

works fine - thanks :)

Have one more question - how add to this filter: "not broadcast and not multicast and not src net" exception "".

Overall idea is: want ignore all local network traffic with exception of traffic beetwen IP "" (on is working WS) and Internet. In Internet traffic want ignore IP from range and (beacuse hosts from this IP ranges are trusted for me).

(27 Apr '16, 05:34) myszoor

not broadcast and not multicast and (not src net or src host

(27 Apr '16, 05:36) sindy

Hi all, is it correct the below filter for his aim in your opinion ?

(not broadcast and not multicast and not ip src net or (not ip net or not ip net

Have a nice day

permanent link

answered 27 Apr '16, 05:16

ValerioItaly's gravatar image

accept rate: 0%

It is not correct at least because not ip net is true also for e.g. broadcast packets, and not broadcast is true for any non-broadcast packet including one from/to, so (simplified for illustration) not broadcast or not ip net would cause both broadcast packets and packets to/from to be captured. For similar reason, not net X or not net Y would let through everything (unless networks X and Y overlap in some way).

@grahamb's answer is the closest one so far. Let's wait for OP's update and eventually adjust that one accordingly. But basically ((not src net or src net is a way to exclude packets whose src ip is in range to from the capture.

(27 Apr '16, 05:34) sindy
Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here



Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text]( "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:


question asked: 27 Apr '16, 04:14

question was seen: 13,724 times

last updated: 27 Apr '16, 05:37

p​o​w​e​r​e​d by O​S​Q​A