This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

I need some help... I'm trying to only capture packets that have the IP ID of 4567. I'm having trouble setting the correct Capture flag. Right now I'm trying to work with IP[4] = 0x11D7. Can I just get some help to put me in the right direction? Thanks guys

asked 07 Mar '17, 09:15

Kickinitlegit's gravatar image

Kickinitlegit
11114
accept rate: 0%


Google of "tcpdump filters ip id" found me this.

Basically you need to specify the offset and length of the field, i.e.

ip[4:2] == 0x11d7
permanent link

answered 07 Mar '17, 09:31

grahamb's gravatar image

grahamb ♦
19.8k330206
accept rate: 22%

Yep, that was it, i was forgetting the length... Thank you sir!

(07 Mar '17, 09:58) Kickinitlegit
Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×1,620
×549
×349
×178
×11

question asked: 07 Mar '17, 09:15

question was seen: 2,875 times

last updated: 07 Mar '17, 09:58

p​o​w​e​r​e​d by O​S​Q​A