Display Filter Reference: File Transfer Protocol (FTP)

Protocol field name: ftp

Versions: 1.0.0 to 2.6.2

Back to Display Filter Reference

Field name Description Type Versions
ftp-data.command Command Character string 2.6.0 to 2.6.2
ftp-data.command-frame Command frame Frame number 2.6.0 to 2.6.2
ftp-data.current-working-directory Current working directory Character string 2.6.0 to 2.6.2
ftp-data.setup-frame Setup frame Frame number 2.6.0 to 2.6.2
ftp-data.setup-method Setup method Character string 2.6.0 to 2.6.2
ftp.active.cip Active IP address IPv4 address 1.0.0 to 2.6.2
ftp.active.nat Active IP NAT Boolean 1.0.0 to 2.6.2
ftp.active.port Active port Unsigned integer, 2 bytes 1.0.0 to 2.6.2
ftp.command Command Character string 2.6.0 to 2.6.2
ftp.command-frame Command frame Frame number 2.6.0 to 2.6.2
ftp.command-response.bitrate Response bitrate Unsigned integer, 4 bytes 2.6.0 to 2.6.2
ftp.command-response.bytes Command response bytes Unsigned integer, 4 bytes 2.6.0 to 2.6.2
ftp.command-response.duration Response duration Unsigned integer, 4 bytes 2.6.0 to 2.6.2
ftp.command-response.first-frame-num Command response first frame Frame number 2.6.0 to 2.6.2
ftp.command-response.frames Command response frames Unsigned integer, 4 bytes 2.6.0 to 2.6.2
ftp.command-response.last-frame-num Command response last frame Frame number 2.6.0 to 2.6.2
ftp.current-working-directory Current working directory Character string 2.6.0 to 2.6.2
ftp.eprt.af Extended active address family Unsigned integer, 1 byte 1.10.0 to 2.6.2
ftp.eprt.args_invalid EPRT arguments must have the form: |||| Label 1.12.0 to 2.6.2
ftp.eprt.ip Extended active IP address IPv4 address 1.10.0 to 2.6.2
ftp.eprt.ipv6 Extended active IPv6 address IPv6 address 1.10.0 to 2.6.2
ftp.eprt.port Extended active port Unsigned integer, 2 bytes 1.10.0 to 2.6.2
ftp.epsv.args_invalid EPSV arguments must have the form (||||) Label 1.12.0 to 2.6.2
ftp.epsv.ip Extended passive IPv4 address IPv4 address 1.10.0 to 2.6.2
ftp.epsv.ipv6 Extended passive IPv6 address IPv6 address 1.10.0 to 2.6.2
ftp.epsv.port Extended passive port Unsigned integer, 2 bytes 1.10.0 to 2.6.2
ftp.passive.ip Passive IP address IPv4 address 1.0.0 to 2.6.2
ftp.passive.nat Passive IP NAT Boolean 1.0.0 to 2.6.2
ftp.passive.port Passive port Unsigned integer, 2 bytes 1.0.0 to 2.6.2
ftp.request Request Boolean 1.0.0 to 2.6.2
ftp.request.arg Request arg Character string 1.0.0 to 2.6.2
ftp.request.command Request command Character string 1.0.0 to 2.6.2
ftp.response Response Boolean 1.0.0 to 2.6.2
ftp.response.arg Response arg Character string 1.0.0 to 2.6.2
ftp.response.code Response code Unsigned integer, 4 bytes 1.0.0 to 2.6.2
ftp.response.code.invalid Invalid response code Label 2.4.0 to 2.6.2
ftp.response.pwd.invalid Invalid PWD response Label 2.6.0 to 2.6.2
ftp.setup-frame Setup frame Frame number 2.6.0 to 2.6.2
Go Beyond with Riverbed Technology

Riverbed is Wireshark's primary sponsor and provides our funding. They also make great products that fully integrate with Wireshark.

I have a lot of traffic...

ANSWER: SteelCentral™ Packet Analyzer PE
  • • Visually rich, powerful LAN analyzer
  • • Quickly access very large pcap files
  • • Professional, customizable reports
  • • Advanced triggers and alerts
Learn More

Buy Now

No, really, I have a LOT of traffic…

ANSWER: SteelCentral™ NetShark appliance
  • • Troubleshoot problems faster
  • • Quickly identify the applications running on your network
  • • Monitor your virtual machine traffic
Learn More