A tcpdump Tutorial and Primer
danielmiessler.com
danielmiessler.com
You can cut away huge swaths of troubleshooting areas just by watching what is on the wire. There are problems you just won't find without knowing how to use a sniffer. I once had a core router dropping packets because of a flawed ACL implementation (It would treat fragmented packets as if they had port numbers at the matching payload offset).
Knowing how to use a packet sniffer makes hard problems so easy it feels like cheating.
- -A is equivalent to -X displaying the payload of the packet in ASCII format. If you want to do some scripting based on a payload, that's very handy for matching specific pattern (don't forget offset notation '[a:b]' is limited to 4 bytes block in the bpf filter)
- -tttt if you want to print the complete time-stamp per packet
- Don't forget that TCP offloading might have an impact when doing packet capture (and analysis) http://sandilands.info/sgordon/segmentation-offloading-with-...
- When capturing on a long period of time, the -G or -C helps to rotate capture files while capturing. tcpdump -i en1 -s 0 -G 60 -w tst%y%m%d%H%M%S.cap (if you want to rotate the file every 60 secs) or -C to do the rotation based of the size of the capture file.
- There are many tcpdump forks (OpenBSD tcpdump is slightly different than the tcpdump on Debian)
Personally I prefer dumpcap and wireshark for this, but it's similar.
What is peoples obsession with stretching command line tools? Wake up! We have retina displays now. To display stuff.
I use Wireshark when I need to. I prefer to type a few characters in the command line if that's enough to get the right answer.
Sometimes you just need to know if DNS resolution is working.
Or if the right DNS server is queried.
Or if some server backend is actually firing off packets to the proper place when you hit a button on the frontend.
Or you just need to verify that data are coming in when the guy on the phone says "check again now".
For these sort or problems, tcpdump is great, as it easily allows you to experiment with different filters on the command line, which will take you an order of magnitude more time click through in wireshark or wait for reparsing if you use a display filter.
I mean, I'm all for having nice GUI tools. And I've even been known to stare at giant data dumps when stumped (though I'll note that a maximized terminal window with grep-over-tcpdump-output content works just as well as wireshark for that purpose). But that argument is just silly.
Also people are lazy.
This might be a useful addition to the links at the bottom of your page: