当前位置:网站首页>Wireshark filter rule

Wireshark filter rule

2022-06-12 05:28:00 Gradually every day, I miss my hometown a little more

In the development of network We are indispensable Tool is wireshark, He can catch Packets above the link layer .

In the mass of packets How to quickly find the package we want to see , For example, according to protocol - tcp udp  arp igmp  http smtp etc. These are written from the link to the application layer . 

Here we have a little trick

  You need to filter according to the mark of that layer It's just wireshark filter On ip. At the beginning list Display the supported filter items .

For example, you need to filter ip.

  The link layer Keyword filtering

Transport layer :

  

The link layer contains another wirless 

 

We won't go into details about others Let's just say wlan Some filtering strategies

Ann mac Filter : 

   wan.addr / wlan contains 00:f0:12:24:35:88

Ann wifi Filter the type of package :

     wlan.fc.type_subtype==0x0   

原网站

版权声明
本文为[Gradually every day, I miss my hometown a little more]所创,转载请带上原文链接,感谢
https://yzsam.com/2022/03/202203010616409355.html