TCPDump Commands Howsnip

A Complete TCPDump Guide for Network Administrators

TCPDump is one of the most widely used command-line tools for capturing and analyzing network traffic on Linux and Unix-based systems. Whether you’re troubleshooting connectivity issues, monitoring network activity, or investigating security incidents, TCPDump provides a powerful way to inspect packets directly from the terminal.

In this tutorial, you’ll learn how to use common TCPDump commands to capture, filter, save, and analyze network packets. The examples are suitable for beginners while also covering several advanced filtering techniques used by network administrators and security professionals.

Prerequisite: TCPDump must be installed on your system, and you may need administrative or root privileges to capture packets on network interfaces.

  1. Capture Packets on a Specific Network Interface
  2. Capture Packets with Detailed Output
  3. View Packets in HEX and ASCII Format
  4. Save Captured Traffic to a PCAP File
  5. Read Packets from a Saved Capture File
  6. Display IP Addresses Instead of Hostnames
  7. Filtering Traffic by IP Address
  8. Filter Traffic by Port
  9. Capture Traffic for an Entire Network
  10. Filter Packets by Size
  11. Advanced TCPDump Filtering
  12. Capture Traffic from a Specific Host to a Specific Port
  13. Capture Traffic Between Multiple Networks
  14. Capture Traffic While Excluding a Specific Port
  15. Use Parentheses in Complex Filters

1. Capture Packets on a Specific Network Interface

To start capturing packets on a particular interface, use the -i option followed by the interface name.

tcpdump -i ens33

This command captures all traffic flowing through the ens33 interface.

TCPDump Commands Howsnip

Note: If your system only has a single active network interface, running tcpdump without the -i option may also work.

2. Capture Packets with Detailed Output

For more detailed packet information, combine several output options.

tcpdump -i ens33 -nnvvS

TCPDump Commands Howsnip

Here’s what these options do:

  • -n prevents hostname resolution.
  • -nn prevents both hostname and service name resolution.
  • -vv increases verbosity.
  • -S displays absolute TCP sequence numbers.

This output is useful when troubleshooting network connections and protocol behavior.

3. View Packets in HEX and ASCII Format

To inspect packet contents in both hexadecimal and ASCII formats, use:

tcpdump -XX -i ens33

TCPDump Commands Howsnip

This command helps when examining packet payloads or troubleshooting application-level communication.

4. Save Captured Traffic to a PCAP File

You can write captured packets to a file for later analysis.

tcpdump -w filename.pcap -i ens33

TCPDump Commands Howsnip

The resulting .pcap file can be opened with tools such as Wireshark or other packet analysis applications.

Important: Saving traffic to a file is often preferable when investigating issues that require deeper analysis later.

5. Read Packets from a Saved Capture File

To review packets from a previously saved capture:

tcpdump -tttt -r savedfile.pcap

TCPDump Commands Howsnip

Command options:

  • -r reads packets from a capture file.
  • -tttt displays a detailed timestamp for each packet.

This is useful when reviewing historical network activity without performing a live capture.

6. Display IP Addresses Instead of Hostnames

To avoid DNS lookups and display only IP addresses:

tcpdump -n -i ens33

TCPDump Commands Howsnip

Disabling name resolution can make output easier to read and improve capture performance.

7. Filtering Traffic by IP Address

One of TCPDump’s most useful features is the ability to filter traffic.

a) Capture Traffic from a Specific Source IP

tcpdump src 192.168.1.1

TCPDump Commands Howsnip

This displays packets originating from 192.168.1.1.

b) Capture Traffic to a Specific Destination IP

tcpdump dst 192.168.1.1

TCPDump Commands Howsnip

This displays packets being sent to 192.168.1.1.

8. Filter Traffic by Port

a) Capture Traffic from a Source Port

tcpdump src port 53

TCPDump Commands Howsnip

This captures traffic originating from port 53, commonly used by DNS servers.

b) Capture Traffic to a Destination Port

tcpdump dst port 22

TCPDump Commands Howsnip

This captures packets destined for port 22.

c) Capture Traffic To or From a Port

tcpdump port 8080

This captures all traffic using port 8080, regardless of direction. This type of filtering is often used when monitoring application-specific traffic.

TCPDump Commands Howsnip

9. Capture Traffic for an Entire Network

You can monitor traffic for a subnet using CIDR notation.

tcpdump net 10.228.12.0/24

TCPDump Commands Howsnip

This captures traffic associated with the 192.168.1.0/24 network.

10. Filter Packets by Size

TCPDump can filter packets based on their size.

a) Show Packets Smaller Than 64 Bytes

tcpdump less 64

TCPDump Commands Howsnip

b) Show Packets Larger Than 256 Bytes

tcpdump greater 256

TCPDump Commands Howsnip

These filters can help identify unusually small or large packets during network analysis.

11. Advanced TCPDump Filtering

TCPDump supports logical operators such as:

  • and
  • or
  • not

These operators allow you to create powerful filtering expressions.

Note: Complex filters may need to be enclosed in single quotes to prevent the shell from interpreting special characters.

12. Capture Traffic from a Specific Host to a Specific Port

Capture all traffic from a source IP with a destination port of 80:

tcpdump -nnvvS src 192.168.1.10 and dst port 80

TCPDump Commands Howsnip

This is useful when troubleshooting web traffic generated by a particular device.

13. Capture Traffic Between Multiple Networks

Capture traffic originating from the 172.16.0.0/16 network and destined for either 192.168.1.0/24 or 10.0.0.0/8:

tcpdump src net 172.16.0.0/16 and dst net 192.168.1.0/24 or 10.0.0.0/8

TCPDump Commands Howsnip

This filter is helpful when monitoring communication between multiple network segments.

14. Capture Traffic While Excluding a Specific Port

To capture all traffic from a host except traffic destined for port 22:

tcpdump -i ens33 'src host 10.228.1.179 and not dst port 22'

TCPDump Commands Howsnip

The not operator allows you to exclude unwanted traffic from your capture results.

15. Use Parentheses in Complex Filters

For more advanced filtering logic, enclose expressions in single quotes. The following command captures traffic from 192.168.1.1 destined for either port 80 or port 21:

tcpdump 'src 192.168.1.1 and (dst port 80 or 21)'

TCPDump Commands Howsnip

Parentheses help group conditions and ensure the filter is evaluated correctly.

Conclusion

TCPDump is a powerful and flexible tool for capturing and analyzing network traffic directly from the command line.

By learning how to capture packets, save traffic to PCAP files, filter by IP addresses and ports, and build advanced filter expressions, you can diagnose network issues more efficiently and gain deeper visibility into network activity.

Keeping these essential TCPDump commands handy will make troubleshooting and traffic analysis significantly easier.