Skip to content

tcpdump & Wireshark

Capturing and analyzing network packets is a foundational skill for diagnosing connectivity issues, identifying malicious activity, and optimizing performance. Tools like tcpdump and Wireshark provide granular visibility into the Linux network stack, enabling administrators to inspect raw packet data, filter traffic, and decode protocols. This section covers practical techniques for capturing, analyzing, and troubleshooting network traffic using these tools.


Capturing Network Traffic with tcpdump

tcpdump is a command-line packet sniffer that captures traffic on a network interface and outputs it in human-readable or raw format. It is ideal for quick diagnostics and scripted analysis.

Basic Capture Commands

To start capturing packets on a specific interface (e.g., eth0):

sudo tcpdump -i eth0
This displays packets in real time. Use Ctrl+C to stop the capture.

To save the capture to a file for later analysis:

sudo tcpdump -i eth0 -w capture.pcap
Use tcpdump -r capture.pcap to replay the file.

Filtering Traffic

Use Berkeley Packet Filter (BPF) syntax to narrow down the capture: - Capture HTTP traffic:

sudo tcpdump -i eth0 port 80
- Capture DNS queries:
sudo tcpdump -i eth0 udp port 53
- Capture traffic to a specific IP:
sudo tcpdump -i eth0 dst 192.168.1.100

Advanced Options

  • Limit capture duration: -duration 30 to stop after 30 seconds.
  • Display summary only: -q for quick output.
  • Decode protocols: Use -nn to disable DNS resolution or -v for verbose output.

Analyzing Captures with Wireshark

Wireshark is a graphical packet analyzer that provides deep inspection of capture files (.pcap/.pcapng). It supports protocol decoding, statistical analysis, and custom filtering.

Opening Captures

  1. Launch Wireshark and select File > Open to load a .pcap file.
  2. Use the Filter bar to apply display filters (e.g., http, tcp.port == 80, or ip.addr == 192.168.1.1).

Key Features

  • Packet Details Pane: Expands to show protocol-specific fields (e.g., TCP headers, DNS queries).
  • Hex Dump View: Inspects raw packet data for anomalies or corruption.
  • Follow TCP Stream: Reassembles TCP sessions to inspect application-layer data.
  • Expert Analysis: Highlights potential issues like retransmissions or malformed packets.

Example: Debugging a DNS Issue

  1. Open a capture containing DNS traffic.
  2. Apply filter dns and inspect the DNS Query section.
  3. Check for Query status: NXDOMAIN to identify unresolved hostnames.

Advanced Techniques and Filters

Custom Display Filters

Combine multiple conditions using logical operators: - tcp.port == 80 and http (HTTP traffic) - tcp.flags.syn == 1 and tcp.flags.ack == 0 (TCP SYN packets) - ip.src == 192.168.1.5 or ip.dst == 192.168.1.5 (traffic involving a specific host)

Using tcpdump with Wireshark

Export filtered packets from tcpdump for Wireshark:

sudo tcpdump -i eth0 port 443 -w https_capture.pcap
Then open https_capture.pcap in Wireshark for detailed analysis.


Troubleshooting Common Issues

  1. Permission Denied: Use sudo to capture traffic on interfaces requiring elevated privileges.
  2. Incorrect Interface: Verify the interface name with ip a or ifconfig before capturing.
  3. Large Capture Files: Use -z to compress captures or split them with tcpdump -w capture.pcap -C 100 (100MB files).
  4. No Traffic Captured: Ensure the interface is active and traffic is flowing (e.g., check with ping or curl).

Key takeaways

  • Use tcpdump for lightweight, scriptable packet capture with BPF filters.
  • Wireshark provides deep protocol analysis, making it ideal for complex troubleshooting.
  • Combine both tools: capture with tcpdump and analyze with Wireshark for efficiency.
  • Apply display filters and expert analysis in Wireshark to isolate anomalies.
  • Always verify interface names and permissions when capturing traffic.