Tcpdump to capture Ethernet frames

How can I use tcpdump to capture Ethernet frames and display any frame sent or received by the local computer using one of the UDP, ARP, and ICMP protocols.

I tried this command:

sudo tcpdump -e udp or arp or icmp

but I think this is wrong.

+4
source share
1 answer

First of all, you are interested in packages, not frames. Frames are the layer below the packages, and only chip makers belong to them. Secondly, you must indicate that your interface with the switch -ior promiscuous mode will not even be activated so that you can see everything - if you need it.

0
source

Source: https://habr.com/ru/post/1542227/


All Articles