Path: csiph.com!usenet.pasdenom.info!aioe.org!.POSTED!not-for-mail From: Ralph Spitzner Newsgroups: comp.os.linux.networking Subject: Re: documentation for tcpdump Date: Sun, 25 Mar 2012 09:22:42 +0200 Organization: Hanswurst & Kaspar Hauser Ltd. Lines: 32 Message-ID: <2nt249-4eg.ln1@spitzner.org> References: <4f6ebc0b$1@x-privat.org> NNTP-Posting-Host: b+aKKuYdKBi6V1N/f0Vc9w.user.speranza.aioe.org Mime-Version: 1.0 Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit X-Complaints-To: abuse@aioe.org User-Agent: Mozilla/5.0 (X11; Linux i686; rv:11.0) Gecko/20120312 Firefox/11.0 SeaMonkey/2.8 X-Notice: Filtered by postfilter v. 0.8.2 Xref: csiph.com comp.os.linux.networking:1209 ghand wrote: > there are three different kinds of qualifier. > type, dir, proto > > When I go to the man page, I don't see the word "qualifier" > > The man page does not mention the keyword portrange > But it is mentioned here > http://www.msamir.net/the-art-of-network-debugging-with-tcpdump/ Are you referring to: expression selects which packets will be dumped. If no expression is given, all packets on the net will be dumped. Otherwise, only packets for which expression is `true' will be dumped. For the expression syntax, see pcap-filter(7). ??? -rasp -- See why I hate Windows users? All pain, no gain. -Howard Chu