tcpdump & Wireshark
Capturing and analyzing network packets is a foundational skill for diagnosing connectivity issues, identifying malicious activity, and optimizing performance. Tools like tcpdump and Wireshark provide granular visibility into the Linux network stack, enabling administrators to inspect raw packet data, filter traffic, and decode protocols. This section covers practical techniques for capturing, analyzing, and troubleshooting network traffic using these tools.
Capturing Network Traffic with tcpdump¶
tcpdump is a command-line packet sniffer that captures traffic on a network interface and outputs it in human-readable or raw format. It is ideal for quick diagnostics and scripted analysis.
Basic Capture Commands¶
To start capturing packets on a specific interface (e.g., eth0):
Ctrl+C to stop the capture.
To save the capture to a file for later analysis:
Usetcpdump -r capture.pcap to replay the file.
Filtering Traffic¶
Use Berkeley Packet Filter (BPF) syntax to narrow down the capture: - Capture HTTP traffic:
- Capture DNS queries: - Capture traffic to a specific IP:Advanced Options¶
- Limit capture duration:
-duration 30to stop after 30 seconds. - Display summary only:
-qfor quick output. - Decode protocols: Use
-nnto disable DNS resolution or-vfor verbose output.
Analyzing Captures with Wireshark¶
Wireshark is a graphical packet analyzer that provides deep inspection of capture files (.pcap/.pcapng). It supports protocol decoding, statistical analysis, and custom filtering.
Opening Captures¶
- Launch Wireshark and select File > Open to load a
.pcapfile. - Use the Filter bar to apply display filters (e.g.,
http,tcp.port == 80, orip.addr == 192.168.1.1).
Key Features¶
- Packet Details Pane: Expands to show protocol-specific fields (e.g., TCP headers, DNS queries).
- Hex Dump View: Inspects raw packet data for anomalies or corruption.
- Follow TCP Stream: Reassembles TCP sessions to inspect application-layer data.
- Expert Analysis: Highlights potential issues like retransmissions or malformed packets.
Example: Debugging a DNS Issue¶
- Open a capture containing DNS traffic.
- Apply filter
dnsand inspect the DNS Query section. - Check for
Query status: NXDOMAINto identify unresolved hostnames.
Advanced Techniques and Filters¶
Custom Display Filters¶
Combine multiple conditions using logical operators:
- tcp.port == 80 and http (HTTP traffic)
- tcp.flags.syn == 1 and tcp.flags.ack == 0 (TCP SYN packets)
- ip.src == 192.168.1.5 or ip.dst == 192.168.1.5 (traffic involving a specific host)
Using tcpdump with Wireshark¶
Export filtered packets from tcpdump for Wireshark:
https_capture.pcap in Wireshark for detailed analysis.
Troubleshooting Common Issues¶
- Permission Denied: Use
sudoto capture traffic on interfaces requiring elevated privileges. - Incorrect Interface: Verify the interface name with
ip aorifconfigbefore capturing. - Large Capture Files: Use
-zto compress captures or split them withtcpdump -w capture.pcap -C 100(100MB files). - No Traffic Captured: Ensure the interface is active and traffic is flowing (e.g., check with
pingorcurl).
Key takeaways¶
- Use
tcpdumpfor lightweight, scriptable packet capture with BPF filters. - Wireshark provides deep protocol analysis, making it ideal for complex troubleshooting.
- Combine both tools: capture with
tcpdumpand analyze with Wireshark for efficiency. - Apply display filters and expert analysis in Wireshark to isolate anomalies.
- Always verify interface names and permissions when capturing traffic.