Tcpdump examples in Linux

When the network is not working as it should, or you just need to understand what exactly is being transmitted over the wires, tcpdump comes to the rescue. It's like a stethoscope for your server — a tool that allows you to “listen” to network traffic in real time. It may seem complicated at first glance, but in reality it is a very powerful and reliable assistant for system administrators and any curious Linux user.

Govee Many GEOsGovee Many GEOs

In this article, we won't delve into network theory. Instead, we'll get straight to the point and look at specific examples of commands that you can use in your daily work. You'll learn how to filter packets by IP address, port, and protocol type to quickly find the information you need in a sea of network data.

Our examples will help you diagnose connection problems, track suspicious activity, or simply satisfy your curiosity about how programs communicate with each other. Let's start with the simplest commands and gradually move on to more advanced use cases.

Tcpdump is a useful utility in Linux for listening to and analyzing network traffic, often used by administrators and developers to understand what is happening on the network: for example, why a service is not working, who is loading the channel, or whether there are any suspicious connections. With simple commands, you can filter traffic by IP, ports, protocols, or interfaces, save it for further analysis, or view it in real time. It's like connecting to a conversation between computers and understanding what they are communicating about.

For the average salary at the enterprise.

Redmagic WWRedmagic WW

Most developers of Linux-based operating systems include the tcpdump utility in the list of pre-installed utilities, but if for some reason it is missing from your distribution, you can always download and install it via “Terminal”. If you have a Debian-based OS, such as Ubuntu, Linux Mint, Kali Linux, and the like, you need to run this command:

sudo apt install tcpdump

During installation, you will need to enter a password. Please note that it will not be displayed as you type it, and you will need to enter the character “D” and press As you can see, they are applied in the same way, the only difference being the name of the filter..

Example:

sudo yam install tcpdump

Once the utility is installed, you can start using it right away. This and much more will be discussed later in the text.

Syntax

Sunsky-online WWhidemyname

Like any other command, tcpdump has its own syntax. Knowing it, you will be able to set all the necessary parameters that will be taken into account when executing the command. The syntax is as follows:

tcpdump options -i interface filters

When using the command, you must specify the interface to track. Filters and options are not mandatory variables, but they allow for more flexible configuration.

Options

Although it is not necessary to specify the option, it is still necessary to list the available ones. The table does not show the entire list, only the most popular ones, but they are more than enough to solve most of the tasks at hand.

Option Definition
-A Allows you to sort packets with ASCII format
-l Adds a scroll function
-i After entering, you need to specify the network interface that will be monitored. To start monitoring all interfaces, enter the word “any” after the option
-c Sudo tcpdump -i ppp0 dst host google-public-dns-a.google.com
-w Generates a text file with the verification report
-e Shows the Internet connection level of the data packet
-L Displays only those protocols that are supported by the specified network interface
-C Creates another file during packet recording if its size exceeds the specified size
-r Opens a file for reading that was created using the -w option
-j The TimeStamp format will be used to record packets
-J Allows you to view all available TimeStamp formats.
-G Used to create a log file. The option also requires specifying a time value, after which a new log will be created
-v, -vv, -vvv Depending on the number of characters in the option, the command output will become more detailed (the increase is directly proportional to the number of characters).
-f Shows the domain name of IP addresses in the output
-F Allows you to read information not from the network interface, but from the specified file.
-D Displays all network interfaces that can be used
-n Disables the display of domain names.
-Z Specifies the user under whose account all files will be created.
-K Skip checksum analysis
-q Display brief information
-H Allows you to detect 802.11s headers
-I Used when capturing packets in monitor mode.

Having discussed the options, we will now move on to their applications. For now, we will look at the filters.

Filters

As mentioned at the beginning of the article, you can add filters to the tcpdump syntax. Now we will look at the most popular ones:

Filter Definition
host Used to specify the host name.
net Specifies the IP subnet and network.
ip Used to specify the protocol address
src Displays packets that were sent from the specified address
dst Outputs packets that were received by the specified address.
arp, udp, tcp Filtering by one of the protocols.
port Displays information related to a specific port.
and, or Used to combine several filters in a command.
less, greater Output packets smaller or larger than the specified size

All of the above filters can be combined with each other, so that the command output will only show the information you want to see. To understand the use of the above filters in more detail, it is worth giving some examples.

Examples of use

nubia Many GEOsnubia Many GEOs

Below are some frequently used syntax options for the tcpdump command. It is not possible to list them all, as there are an infinite number of variations.

Viewing the list of interfaces

It is recommended that each user first check the list of all their network interfaces that can be tracked. From the table above, we know that to do this, we need to use the option -D, therefore, execute the following command in the terminal:

sudo tcpdump -D

Example:

As you can see, there are eight interfaces in the example that can be viewed using the tcpdump command. The article will provide examples with ppp0, you can use any other filter.

Normal traffic capture

If you need to track a single network interface, you can do so using the option -i. Don't forget to specify the interface name after entering it. Here is an example of executing such a command:

sudo tcpdump -i ppp0

Please note: you need to enter “sudo” before the command itself, as it requires superuser rights.

Example:

Note: after pressing Enter in the “Terminal”, the captured packets will be displayed continuously. To stop their flow, press the Ctrl+C key combination.

If you execute the command without additional options and filters, you will see the following format for displaying tracked packets:

22:18:52.597573 IP vrrp-topf2.p.mail.ru. https > 10.0.6.67.35482: Flags [P.], seq 1:595, ack 1118, win 6494, options [nop,nop,TS val 257060077 ecr 697597623], length 594

Where the color is highlighted:

Blue Packet reception time
Orange Protocol version
Green Sender address
Purple Recipient's address
Gray Additional information about tcp
Red Packet size (displayed in bytes)

This syntax has the ability to output in the window Terminal without using additional options.

Traffic capture with the -v option

As can be seen from the table, the option -v allows you to increase the amount of information. Let's look at an example. Let's check the same interface:

sudo tcpdump -v -i ppp0

Example:

Here you can see that the following line has appeared in the output:

IP (tos 0x0, ttl 58, id 30675, offset 0, flags [DF], proto TCP (6), length 52

Where the color highlights:

Orange Protocol version
Blue Protocol lifetime
Green Header field length
Purple TCP packet version
Red Package size (displayed in bytes)

You can also add the following option to the command syntax -vv or -vvv, which will further increase the amount of information displayed on the screen.

Options -w and -r

The options table mentioned the ability to save all output data to a separate file so that it can be viewed later. This is done with the option -w. It is quite simple to use, just specify it in the command, and then enter the name of the future file with the extension “.pcap”. Let's look at an example:

sudo tcpdump -i ppp0 -w file.pcap

Example:

Please note: while logging to the file, no text is displayed on the Terminal screen.

When you want to view the recorded output, you need to use the option -r, followed by the name of the previously recorded file. It is applied without other options and filters:

sudo tcpdump -r file.pcap

Example:

Both of these options are great for when you need to save large amounts of text for later analysis.

IP filtering

From the filter table, we know that dst allows you to display on the console screen only those packets that were received by the address specified in the command syntax. This makes it very convenient to view the packets received by your computer. To do this, you just need to specify your IP address in the command:

sudo tcpdump -i ppp0 ip dst 10.0.6.67

Example:

As you can see, in addition to dst, we also specified the filter in the command ip. In other words, we told the computer to pay attention to the IP address of the packets when selecting them, rather than other parameters.

You can filter outgoing packets by IP. In the example, we will use our IP again. That is, now we will track which packets are sent from our computer to other addresses. To do this, execute the following command:

sudo tcpdump -i ppp0 ip src 10.0.6.67

Example:

As you can see, we changed the filter in the command syntax. dst on src, this tells the machine to search for the sender by IP.

Filtering by HOST

By analogy with IP, we can specify the filter host, to filter out packets with the host of interest. That is, in the syntax, instead of the sender/recipient's IP address, you will need to specify its host. It looks like this:

sudo tcpdump -i ppp0 dst host google-public-dns-a.google.com

Example:

In the image, you can see that in “Terminal” only those packets that were sent from our IP to the host google.com are displayed. As you can see, instead of the host google, you can enter any other.

As with IP filtering, in the syntax dst can be replaced with src, to see the packets that are sent to your computer:

sudo tcpdump -i ppp0 src host google-public-dns-a.google.com

Please note: the host filter must come after dst or src, otherwise the command will return an error. In the case of IP filtering, on the contrary, dst and src come before the ip filter.

Applying the and and or filters

If you need to use several filters in one command, you need to apply the filter and or or (depends on the case). By specifying filters in the syntax and separating them with this operator, you will “force” them to work as one. Here is an example:

sudo tcpdump -i ppp0 ip dst 95.47.144.254 or ip src 95.47.144.254

Example:

The command syntax shows that we want to display “Terminal” all packets that were sent to the address 95.47.144.254 and packets received by the same address. You can also change some variables in this expression. For example, instead of IP, specify HOST or replace the addresses themselves.

The port and portrange

Filter port) filters are great for when you need to get info on packets with a specific port. So, if you only need to see DNS responses or requests, you need to specify port 53:

adds scroll function

Example:

If you want to view http packets, you need to enter port 80:

sudo tcpdump -vv -i ppp0 port 80

Example:

Among other things, it is possible to track a range of ports at once. To do this, use the filter portrange:

sudo tcpdump portrange 50-80

As you can see, in conjunction with the filter portrange it is not necessary to specify additional options. It is enough to just set the range.

Filtering by protocols

“From file” udp:

sudo tcpdump -vvv -i ppp0 udp

Example:

As you can see in the image, after executing the command in “Terminal” only packages with a protocol are displayed. udp. Accordingly, you can filter by others, for example, arp:

sudo tcpdump -vvv -i ppp0 arp

or tcp:

sudo tcpdump -vvv -i ppp0 tcp

Filter net

Operator net helps filter packets based on their network designation. It is as easy to use as the others — you need to specify the attribute in the syntax net, then enter the network address. Here is an example of such a command:

sudo tcpdump -i ppp0 net 192.168.1.1

Example:

Filtering by packet size

We haven't covered two other interesting filters yet: less and greater. From the filter table, we know that they are used to output data packets larger than (less or less (greater of the size specified after entering the attribute.

Let's say we only want to monitor packets that do not exceed 50 bits, then the command will look like this:

sudo tcpdump -i ppp0 less 50

Example:

Now let's display in “Terminal” packages larger than 50 bits:

sudo tcpdump -i ppp0 greater 50

Example:

As you can see, they are applied in the same way, the only difference being the name of the filter.

As you can see, tcpdump is an incredibly powerful tool for those who need to look under the hood of network interaction. It allows you to see in real time what is actually being transmitted over wires or through the air, turning abstract network problems into concrete data that can be analyzed.

Start with simple commands, such as filtering by port or IP address. Gradually, with practice, you will be able to build more complex filters to accurately capture the packets you need. Don't be afraid to experiment on your test machine — it's the best way to understand how everything works.

Ultimately, knowing how to use tcpdump is a superpower for a system administrator or developer. It gives you independence in diagnosing problems, whether it's a connection failure, suspicious activity, or simply a desire to understand the logic behind a particular network service. This tool will be a reliable assistant in your arsenal.

Italojewerly WWItalojewerly WWItalojewerly WWItalojewerly WWItalojewerly WWItalojewerly WW
What function do you consider the most important in a new smartphone?
Share to friends
Sergey Petrov

Specialization - smart devices for the home. I research and test various smart gadgets, from voice assistants to smart light bulbs. On this site I tell you how these devices can make your home more comfortable and technologically advanced.

Rate author
Appliances News
Add a comment