Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-users: Re: [Wireshark-users] tcpdump forum ?

Date Prev · Date Next · Thread Prev · Thread Next
From: "Aktuna, Ilker, Vodafone Turkey" <ilker.aktuna@xxxxxxxxxxxx>
Date: Thu, 30 Aug 2012 08:10:50 +0000

Yes, the filter worked fine. Thanks.

 

Well,it was working somehow. Maybe some version of libpcap was supporting it, is it impossible ?

I didn’t use tshark. I know that its display filters support this but they are not effective when capturing to file :(

 

Cheers,

ilker

 

 

From: wireshark-users-bounces@xxxxxxxxxxxxx [mailto:wireshark-users-bounces@xxxxxxxxxxxxx] On Behalf Of Sake Blok
Sent: Thursday, August 30, 2012 8:26 AM
To: Community support list for Wireshark
Subject: Re: [Wireshark-users] tcpdump forum ?

 

On 28 aug. 2012, at 15:07, "Aktuna, Ilker, Vodafone Turkey" <ilker.aktuna@xxxxxxxxxxxx> wrote:

 

Sorry if I was misleading. I didn’t state that I could write the patch for “ipip” . I meant that I could compile if the required code is supplied. I thought it was a easy for you to supply the required code. From your recent post I understand that I was wrong. So I’ll try to use what you suggested as a capture filter. (Thanks for the filter by the way)

 

Did the filter work?



 But I wonder how “tcpdump” started not supporting this , as it was working fine on the previous server.

 

Any ideas ?

 

It sounds unlikely that it had ever worked. Are you sure you had ipip traffic back then? Or did you use tshark? Tshark is ipip aware in it's display filters (not in it's capture filters). 

 

Cheers,

Sake


Yasal Uyarı :
Bu elektronik posta işbu linki kullanarak ulaşabileceğiniz Koşul ve Şartlar dokumanına tabidir
http://www.vodafone.com.tr/VodafoneHakkinda/eposta-hukuki-sartlar.php