Ethereal-users: Re: [Ethereal-users] Question about packet filtering

Note: This archive is from the project's previous web site, ethereal.com. This list is no longer active.

From: Richard Urwin <richard@xxxxxxxxxxxxxxx>
Date: Thu, 8 Apr 2004 22:49:08 +0100
On Thursday 08 Apr 2004 9:50 pm, Matthew Bedford wrote:
> I wish to filter traffic during capture for particular protocols,
> such as AIM, for all hosts and IPs. What would the proper syntax be.
> I've tried reading the tcpdump man page (umm, lost...) and I've read
> the help section. I've tried "ether proto AIM" and "ip proto AIM" but
> it keeps saying I'm using incorrect syntax.

The capture syntax only goes as high as TCP or UDP. AIM is above one of 
those. A display filter will work OK. Filter on the addresses to keep 
the size of the capture down.

-- 
Richard Urwin