{
  "id": 12276742,
  "title": "Filter tcpdump by IP: Hosts, Direction, Subnets, and Ports",
  "url": "https://urgent.news/2026/10/06/filter-tcpdump-by-ip-hosts-direction-subnets-and-ports",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-06T01:49:19.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/__3381495fd2b/filter-tcpdump-by-ip-hosts-direction-subnets-and-ports-2egi"
  },
  "original_language": "en",
  "account": "To filter packet captures using tcpdump, start by selecting the correct interface. On Linux, list available capture interfaces using tcpdump -D. Once you've identified the appropriate interface with -i, you can begin filtering the traffic. Use the host keyword to match either direction of traffic involving a specific IP address. For example, sudo tcpdump -nn -i eth0 host 192.0.2.25 captures packets where 192.0.2.25 is either the source or destination. Replace the example address with the relevant one on your system. To filter traffic involving a subnet, use the net keyword with CIDR notation. For example, sudo tcpdump -nn -i eth0 net 192.0.2.0/24 captures packets whose source or destination belongs to the 192.0.2.0/24 network. Remember that the direction qualifier (src or dst) can be added to narrow the filter to one side of the packet. To filter traffic based on port numbers, combine the host keyword with the tcp port number. For example, sudo tcpdump -nn -i eth0 host 192.0.2.25 and tcp port 443 captures TCP traffic involving the address 192.0.2.25 when either TCP port is 443. When using multiple conditions, combine them using and and use parentheses to group conditions appropriately. For instance, sudo tcpdump -nn -i eth0 (host 192.0.2.25 or host 198.51.100.10) and tcp port 443 captures traffic between the specified hosts and port 443. To ensure the filter works as intended, check the assumptions behind it, such as the selected interface, direction of traffic, address and family, and any additional conditions. Permissions might also be required, so run tcpdump with elevated privileges using sudo.",
  "summary": "When a packet capture is full of traffic you don't care about, narrow it with a capture filter . For an IP address, the key distinction is whether you want traffic in both directions, only packets from the address, or only packets going to it. sudo tcpdump -nn -i eth0 'host 192.0.2.25' This captures packets where 192.0.2.25 is either the source or destination. Replace the example address and…",
  "key_points": [
    "Use host keyword to filter by IP address in tcpdump",
    "Apply net keyword with CIDR notation for subnet filtering",
    "Combine host and tcp port numbers for port-based filtering"
  ],
  "editors_take": "Mastering tcpdump filters enables network administrators to precisely capture and analyze relevant packet traffic, streamlining troubleshooting and monitoring by targeting specific hosts, directions, subnets, and ports.",
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}