Urgent.News

What's breaking now, across thousands of outlets.

Tech

Filter tcpdump by IP: Hosts, Direction, Subnets, and Ports

When a packet capture is full of traffic you don't care about, narrow it with a capture filter . For an IP address, the key distinction is whether you want traffic in both directions, only packets from the address, or only packets going to it. sudo tcpdump -nn -i eth0 'host 192.0.2.25' This captures packets where 192.0.2.25 is either the source or destination. Replace the example address and…

To filter packet captures using tcpdump, start by selecting the correct interface. On Linux, list available capture interfaces using tcpdump -D. Once you've identified the appropriate interface with -i, you can begin filtering the traffic. Use the host keyword to match either direction of traffic involving a specific IP address.

For example, sudo tcpdump -nn -i eth0 host 192.0.2.25 captures packets where 192.0.2.25 is either the source or destination. Replace the example address with the relevant one on your system. To filter traffic involving a subnet, use the net keyword with CIDR notation. For example, sudo tcpdump -nn -i eth0 net 192.0.2.0/24 captures packets whose source or destination belongs to the 192.0.2.0/24 network.

Remember that the direction qualifier (src or dst) can be added to narrow the filter to one side of the packet. To filter traffic based on port numbers, combine the host keyword with the tcp port number. For example, sudo tcpdump -nn -i eth0 host 192.0.2.25 and tcp port 443 captures TCP traffic involving the address 192.0.2.25 when either TCP port is 443.

When using multiple conditions, combine them using and and use parentheses to group conditions appropriately. For instance, sudo tcpdump -nn -i eth0 (host 192.0.2.25 or host 198.51.100.10) and tcp port 443 captures traffic between the specified hosts and port 443. To ensure the filter works as intended, check the assumptions behind it, such as the selected interface, direction of traffic, address and family, and any additional conditions. Permissions might also be required, so run tcpdump with elevated privileges using sudo.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

Traefik or Caddy? Choose a Reverse Proxy by How You Deploy

Adding a service behind a reverse proxy should be routine. But the workflow changes depending on whether routes live in one proxy config or are discovered from your containers.

  • Caddy is simpler for small, stable site configurations
  • Traefik suits frequently changing Docker services
  • Routing defined differently: Caddy explicitly, Traefik via metadata labels

My refund handler checked the ledger before paying. It still paid twice.

A refund handler commits the refund, then loses its reply. Maybe the HTTP response timed out. Maybe the worker died before it acknowledged the queue message.

  • Refund handlers check ledger before payment but still pay twice due to various reasons.
  • Four handlers tested: naive always pays twice, others pay correctly once in 200 trials.

More from Tuesday 6 October →