|
|||||||||||
|
RE: WINDUMP SYNTAX ASSISTANCE.....
From: Bill Martin <martin.b(at)attbi.com>
Date: Wed Jan 29 2003 - 02:09:52 EST
windump ((port 80) and (net !192.168.1.0/24))
Change the port,and the net address as needed
-----Original Message-----
Forum, I am looking for the Windump syntax to record only the packets that involve a particular host and those hosts outside of our internal network. I've tried the "host hostname and not src net localnet, but I am still missing half of the traffic as it only gives me ingress traffic. I still need to record egress traffic. So I try host hostname and not dst net localnet. This gives me only egress and not ingress. If I try without same syntax without the src or dst, I get no traffic. Can anyone point me in the right direction with this? Thanks in advance. Regards, Jason M. Beauford. Received on Wed Jan 29 12:24:50 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:07 EDT |
||||||||||
|
|||||||||||