tcpdump command

Andy Green andy at
Fri May 18 14:03:20 UTC 2007

Kaushal Shriyan wrote:
> Thanks Andy
> so running this command tcpdump -i eth0 -s 1500 -w dump host
> www.example.comwill give me the network traffic between src host to
> destination  host
> and destination host to src host
> is that correct what i understand

What it will show you exactly is any packet that is coming from, or
going to  If is also talking to at that time, it will show those packets too.

As David Miller points out you can tighten it using

host and host

but normally in practice nobody else talks to the host you want, and if
they do contaminate your capture, only then do you bother to tighten the
capture criteria accordingly.


More information about the fedora-list mailing list